1
peterr
Weblog version 1.42 - security risk
  • 2006/5/3 6:06

  • peterr

  • Just can't stay away

  • Posts: 518

  • Since: 2004/8/5 9


We were getting lots of pornographic links posted via the weblog module, hundreds. Turned off the permissions, so that anonymous users cannot add to the 'trackback', however this did not stop them, they were still (somehow ??) able to post

Quote:

85.255.114.134 - - [29/Apr/2006:03:35:38 +0000] "POST
/modules/weblog/weblog-tb.php/2 HTTP/1.1" 200 96 "-" "Movable Type"


As we wanted to stop this abuse posting, the quick resolve was to simply delete the file .../weblog/weblog-tb.php , because there was content in the weblog that we wanted to keep and have displayed.

Obviously, the code in the file ../weblog-tb.php is not written in a secure manner, ........ be warned !!
NO to the Microsoft Office format as an ISO standard.
Sign the petition

Login

Who's Online

321 user(s) are online (194 user(s) are browsing Support Forums)


Members: 0


Guests: 321


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits