1
peterr
Weblog version 1.42 - security risk
  • 2006/5/3 6:06

  • peterr

  • Just can't stay away

  • Posts: 518

  • Since: 2004/8/5 9


We were getting lots of pornographic links posted via the weblog module, hundreds. Turned off the permissions, so that anonymous users cannot add to the 'trackback', however this did not stop them, they were still (somehow ??) able to post

Quote:

85.255.114.134 - - [29/Apr/2006:03:35:38 +0000] "POST
/modules/weblog/weblog-tb.php/2 HTTP/1.1" 200 96 "-" "Movable Type"


As we wanted to stop this abuse posting, the quick resolve was to simply delete the file .../weblog/weblog-tb.php , because there was content in the weblog that we wanted to keep and have displayed.

Obviously, the code in the file ../weblog-tb.php is not written in a secure manner, ........ be warned !!
NO to the Microsoft Office format as an ISO standard.
Sign the petition

Login

Who's Online

118 user(s) are online (73 user(s) are browsing Support Forums)


Members: 0


Guests: 118


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits