Page 1 of 1

Bug or not?

Posted: Fri 4. Jun 2004, 11:06
by DrubusCulubus
Hi y'all,

I think I found a small security issue in the guestbook. Perhaps I am a bit late or someone else found it already but ok.

Everybody who has access to the guestbook can use all replacement tags in a message in the guestbook/commentspart. Is that on purpose or should it be more secure?

Anyone has an idea or comment?

Cheers!

Posted: Tue 8. Jun 2004, 23:16
by Oliver Georgi
New release has a fix for it. No PHP possible.

Oliver

Posted: Wed 9. Jun 2004, 05:57
by DrubusCulubus
Thanks Oliver! I'll try it out a.s.a.p.!

Cheers!