Author: you've been HAACKED | Posted on: 11/28/2008 12:59:45 AM | Views : 829

A Subtext user found a security flaw which opens up Subtext to potential XSS attacks via comment. This flaw was introduced in Subtext 2.0 by the feature which converts URLs to anchor tags. If you are still on 1.9.5b or before, you are not affected by this issue. If you upgraded to 2.0, then please update to 2.1 as soon as you can. Note that you can edit comments in the admin section of your blog to fix comments if someone attempts to abuse your comments. This release has several other bug fixes and usability improvements as well. I started to replace the use of UpdatePanel in some areas with straight up jQuery, which ends up reducing bandwidth usage. List of bug fixes and changes: Fixed Medium Trust issue by removing calls to UrlAuthorizationModule...(read more) ...

Go to the complete details ...