Welcome to Geeklog, Anonymous Sunday, December 22 2024 @ 03:00 am EST

News

EasyFile plugin SQL injection

  • Thursday, March 29 2012 @ 12:15 pm EDT
  • Contributed by:
  • Views: 7,816
Security

An SQL injection vulnerability in the EasyFile plugin has been found and published by a user who calls himself Hellboy (the vulnerability is reported as being in Geeklog, but it really only affects the EasyFile plugin).

Given that the EasyFile plugin hasn't been updated in years, we assume that it is no longer maintained. If you use this plugin on your site, we recommend that you uninstall the plugin and remove all the files that belong to it as soon as possible.

We have removed the EasyFile plugin from our download area. If there are any other sites out there mirroring the plugin, please remove it from those sites as well. Thank you.

Dear Profile Spammers ...

  • Saturday, March 24 2012 @ 04:45 am EDT
  • Contributed by:
  • Views: 8,430
Spam

To whoever created those step-by-step instructions on how to add your website link on each of the 50 High Page Rank Authority sites:

  1. Thanks for listing us as a "High Rank Authority site" (whatever that's supposed to mean).
  2. Forget about spamming us.

All profiles are under review and anything that looks remotely spammy will be banned. Stop wasting your money (for paying people in East Asia to spam us) and our time.

Sincerely,
The Geeklog Team

Geeklog 1.8.1

  • Sunday, October 09 2011 @ 01:05 pm EDT
  • Contributed by:
  • Views: 18,336
Announcements

Geeklog 1.8.1 is now available for download. This is a maintenance and recommended upgrade for Geeklog 1.8.0.

This release ships with jQuery 1.6.3, which fixes a possible XSS in that JavaScript library, which shouldn't have affected Geeklog itself, but may potentially exist in add-ons that make extensive use of jQuery. Geeklog 1.8.1 also fixes two cases of information leakage, where the OAuth consumer key and secret were exposed when enabling the "rootdebug" option (which is off by default). Also, the MS SQL driver was displaying full details of SQL errors by default.

Other changes in this release:

Page navigation