<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog House &#187; Warnings</title>
	<atom:link href="http://bloghouse.net/tagged/warnings/feed/" rel="self" type="application/rss+xml" />
	<link>http://bloghouse.net</link>
	<description>A Home for Wayward Blogs</description>
	<lastBuildDate>Sat, 21 Aug 2010 16:29:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>MT vulnerability</title>
		<link>http://bloghouse.net/2003/11/mt-vulnerability/</link>
		<comments>http://bloghouse.net/2003/11/mt-vulnerability/#comments</comments>
		<pubDate>Thu, 27 Nov 2003 10:52:22 +0000</pubDate>
		<dc:creator>Kathy</dc:creator>
				<category><![CDATA[Internet Safety]]></category>
		<category><![CDATA[Warnings]]></category>

		<guid isPermaLink="false">http://bloghouse.net/?p=14</guid>
		<description><![CDATA[<p>There is a vulnerability in MT&#8217;s send-entry program (that is used by blogs that want to have an &#8216;e-mail this article&#8217; option) that could allow spammers to <a href="http://bloghouse.net/2003/11/mt-vulnerability/"  >&#187;&#187;</a>]]></description>
			<content:encoded><![CDATA[<p>There is a vulnerability in MT&#8217;s send-entry program (that is used by blogs that want to have an &#8216;e-mail this article&#8217; option) that could allow spammers to use it.<br />
MT&#8217;s article <a href="http://www.movabletype.org/news/2003_11.shtml#000873">may be found here</a>.<br />
They have issued a fixed mt-send-entry.cgi file (the file affected). All the MT users hosting here at Blog House<strong>have been upgraded</strong>. I decided it would be easier just to upgrade everyone than to bug you to do it. <img src='http://bloghouse.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
However, MT recommends that if you are not using the send-entry option that you remove that file entirely. I would second their recommendation, since their upgrade is more secure but not completely secure.<br />
Many thanks to <a href="http://wizbangblog.com/archives/001198.php">Wizbang</a> for the warning.</p>
]]></content:encoded>
			<wfw:commentRss>http://bloghouse.net/2003/11/mt-vulnerability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

