Security: vulnerability in SPAW editor
Posted by: phpppOn 2007/6/13 4:05:22 24040 readsVulnerability was reported in some version of the SPAW editor, which is used by some of XOOPS third-party modules.
Module "tinycontent" is one of the modules using SPAW. Although we are not sure which version(s) is vulnerable, we suggest disable SPAW in tinycontent and remove the "modules/tinycontent/admin/spaw/" folder from your server.






I already disabled version notification in Zen Cart because I had a raft of demands to upgrade as soon as the new version came out. Upgrades should be the webmaster's decision. They shouldn't be pressurised into it because a client has been panicked by a version 'warning' or a security scare. As long as xoops.org continue to highlight issues like this promptly, webmasters can keep up to speed on security issues. Users can subscribe to the security news category and receive email notifications of new articles. If they don't bother, that's their problem.