Geeklog 1.3.11
- Friday, December 31 2004 @ 12:43 pm EST
- Contributed by: Dirk
- Views: 19,338
- It was possible to submit stories anonymously even if anonymous submissions were turned off in config.php (reported by Barry Wong).
These stories still ended up in the submission queue, though, unless you disabled it in config.php. - Some of the parameters in link and event submissions weren't filtered, leaving them open to potential SQL injections.
- The links for the What's Related block were created from the unfiltered story text, opening the possibility of XSS attacks (reported by Vincent Furia).
This update is strongly recommended for all users of Geeklog 1.3.10 since, in addition to the above security issues, it also fixes quite a few bugs in 1.3.10. Geeklog 1.3.11 is also meant as a replacement for 1.3.10, i.e. there will be no further development for 1.3.10.
Installation instructions follow ...