ACal 2.2.6 Released
This week I decided to fix the two security vulnerabilities reported by one named Alex in ACal 2.2.5.
So first I changed the code so instead of including the header and footer files they would be read as a file instead of as a PHP script. Second, I got rid of the cookie based authentication system and switched it over to session based authentication. I have to remove the "remember me" feature for now but at least the security hole is gone.
But even after looking at the 2.2.x source code, I can hardly believe so many people use ACal, but I guess at least it works, and now that I've released 2.2.6 they can rest in peace.
0 comments:
Post a Comment