[dokuwiki] Re: XSS Vulnerability - Update your discussion plugins!

  • From: Michael Klier <chi@xxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Mon, 2 Feb 2009 08:05:05 +0100

On Mon, Feb 02, 2009 at 07:59:16AM +0100, Stéphane Gully wrote:
> First of all, thank for having fixed this vulnerability.
> I followed you recommendation and I upgraded your plugin to 2009-01-31
> version. However I had a strange problem that seams linked to this
> upgrade:
> Since the upgrade I got lot of spam on my discussions threads although
> I well activated the CAPTCHA protection. I don't know if I'm alone
> with this problem and I don't know if it's really related to this
> upgrade but I would be very welcomed if you could check if your
> modifications could break something on the CAPTCHA protection.

Ah, that little detail slipped through somehow :/. You also have to upgrade
the captcha plugin, as the new discussion plugin is only compatible to the
latest version of the captcha plugin (2008-01-03) and vice versa.

Regards,
        Michael

-- 
Michael Klier

www:    http://www.chimeric.de
jabber: chi@xxxxxxxxxxxxxxxxxx
key:    http://downloads.chimeric.de/chi.asc
key-id: 0x8308F551

Other related posts: