The developer fixed a major exploit in 1.4.6 about 2 years ago, which allowed admin username and password retrieval through the search box. There are still quite a few XSS holes which remain untouched (and probably other more dangerous flaws).
Slightly OT: I see this as a perfect opportunity to advertise my upcoming news panel (NewsMini coming soon!)![]()







Reply With Quote