PHP-Nuke 7.9?
Date: Thursday, June 30, 2005 @ 5:22 PM CDT
Topic: PHP-Nuke


This was posted by nukelite at phpnuke.org and seeing as the WYSIWYG editor has caused varied opinions among all of us i thought it would be a good idea to mirror the article here as a follow-up of what has been discussed around many Nuke related sites including this one.

Hello Nukers! Since the release of the version 7.8 I'm reading some suggestions and complains about some new features introduced in the last versions. One of the most criticized and acclaimed feature is the wysiwyg editor added recently and the changes required on the system to put this baby to work. Some reports I received talks about possible vulnerabilities using the editor, few bugs has been replicated by my side and will be addressed, other can't be replicated on my test systems (Linux and Windows) and can't be completely verified, but I'm working to force the errors replication and to give a solution if needed. I'm working on a new variables validation system that should be added to clean any text that will interact with any PHP-Nuke part. That will solve part of the current problems. Also, I will work with the editor trying to leave it on the system since many people liked it but by securing the input and output, on this process I'll add the feature to the editor to be turned on or off. BB2Nuke 2.0.16 (released today) will be included, and some cosmetic modifications will be made.

There is work in progress to lift the face of the Downloads and Web Links modules and some extra validations and security measures on other modules. Due to the importance to bring a solution to the editor issues I think that this modules changes will be addressed for another version.

Anyway, I appreciate all the suggestions received and bug reports from you. And if you have something to report don't hesitate to do it by submitting it as news, as private message to me or by email (if you know the address).

Users feedbacks can't all be answered individualy but all of them are taken seriously into consideration.





This article comes from Nuke Resources
http://www.nukeresources.com

The URL for this story is:
http://www.nukeresources.com/modules.php?name=News&file=article&sid=1151