It is very embarrassing, but in the patch to the xp\_publish.php file shipped with CopperExport 0.1 and 0.2, I had introduced a security vulnerability that would allow for SQL injection attacks against the gallery. I have released CopperExport 0.2.1. The plugin itself has not changed (except for some additional error reporting), but it is extremely important that you update your xp\_publish.php file!
CopperExport 0.2.1 – security fix
February 24th, 2005 · No Comments
Tags: CopperExport · Security