phpCOIN
RackSpace Hosting

Forum Rules Security Announcements

Security related public announcements by phpCOIN personnel. This forum can NOT be posted to by the public

  Reply to this topicStart new topic

> phpCOIN v1.2.4 Released, Security issues and minor bug-fixes
cantex
Posted: September 06, 2006 06:12 pm
Quote Post


Chief Cook & Bottle Washer
***

Group: Admin
Posts: 3,252
Member No.: 1
Joined: August 25, 2006



phpCOIN v1.2.4 was released today.

It addresses a major security issue if your server has register_globals turned ON, along with a new fix for emailing to groups. The "test mode" admin parameter also disables sending the actual email when you wish to test emailing to clients/groups.

V1.2.4 also addreses a potential http-header-splitting issue discovered by Steven Roddis. I thank Steven for taking the time to nofify us, and to work with us to find a solution.


--------------------
================================================================
Please do not email or PM me with a question:
1: I handle over a thousand emails a day, so chances are yours would be buried in the pile.
2: All questions will only be answered in the support forums, so the answers will be useful to others.

Help will be given to install/configure/use phpCOIN, but not programming help to modify phpCOIN operations. If you are competent enough to make programming changes, you should be competent enough to read the source code and figure things out :)

If you are trying to integrate posted sample code into your website, please take into account any changes in phpCOIN made after the code sample was posted. It is discouraging to spend hours answering questions or trying to track down an issue only to find that the user has a version of phpCOIN that makes the sample irrelevant
PMUsers Website
Top
0 User(s) are reading this topic (0 Guests and 0 Anonymous Users)
0 Members:

Topic Options Reply to this topicStart new topic