Archive for Warnings
MT vulnerability
There is a vulnerability in MT’s send-entry program (that is used by blogs that want to have an ‘e-mail this article’ option) that could allow spammers to use it.
MT’s article may be found here.
They have issued a fixed mt-send-entry.cgi file (the file affected). All the MT users hosting here at Blog Househave been upgraded. I decided it would be easier just to upgrade everyone than to bug you to do it. ![]()
However, MT recommends that if you are not using the send-entry option that you remove that file entirely. I would second their recommendation, since their upgrade is more secure but not completely secure.
Many thanks to Wizbang for the warning.