We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 6726
    • 7,075 Posts
    I had a discussion with Guillaume today - on the french thread about the security patch of document parser (I posted a sticky in the french boards, a translation of Timon’s post - in fact - so that french users wouldn’t miss that) - he suggested we list MODx @secunia.

    Let’s remind that Secunia is "a Danish computer security service provider best known for tracking vulnerabilities in more than 8,000 pieces of software and operating systems. Numbers of "unpatched" vulnerabilities in popular applications are frequently quoted in software comparisons. Regardless of this number, the existence of just one "Highly critical" vulnerability is enough to avoid using an application until it is fixed. Secunia also tracks currently active computer viruses."

    I think his suggestion could be quite interresting,
    What do you think ?
      .: COO - Commerce Guys - Community Driven Innovation :.


      MODx est l'outil id
      • 25663 MODX Staff
      • 12,272 Posts
      Interesting indeed, although I’d prefer to do so at the 1.0 stage... wink
        Ryan Thrash, MODX Co-Founder
        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
        • 6726
        • 7,075 Posts
        Well, exactly what Guillaume added when we discussed it, that maybe it should wait until we have a fairly secure build.. we wouldn’t want to make bad publicity, of course smiley
          .: COO - Commerce Guys - Community Driven Innovation :.


          MODx est l'outil id
          • 21255
          • 215 Posts
          It is already listed: http://secunia.com/product/9369/

          BTW: It is not true, that the discovered bug could be used to retrieve sensitive information from server’s filesystem.

          (I’m sure with 0.9.2. we’ll get a quite secure version of MODx...)
            • 25663 MODX Staff
            • 12,272 Posts
            Fair enough... can you update that report to state what’s not true?
              Ryan Thrash, MODX Co-Founder
              Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
              • 21255
              • 215 Posts
              It’s currently under review at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2006-1821 - let’s see what they think about it... wink