Welcome to Code AuthorsPlease be aware this site is testing a new Your Account module. If you experience any difficulties registering or logging in, please let us know by using the Feedback link so we can investigate any issues.
We have made a considerable number of changes to this site over the last few days and a detailed explanation of those changes can be found in our Announcements forum.
HTML Purifier CSS Cross-Site Scripting and Script Insertion
Posted On Wednesday, June 25, 2008 @ 08:51:56 CEST
in
Security Vulnerabilities
By
Guardian
SECUNIA ADVISORY ID:SA30779
VERIFY ADVISORY:
http://secunia.com/advisories/30779/
Moderately critical
IMPACT:Cross Site Scripting
WHERE:From remote
SOFTWARE:HTML Purifier 2.x
http://secunia.com/product/19145/
HTML Purifier 3.x
http://secunia.com/product/19146/
DESCRIPTION:
Two vulnerabilities have been reported in HTML Purifier, which can be exploited by malicious people to conduct cross-site scripting or script insertion attacks. Input passed to the library containing CSS data is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is viewed. Successful exploitation of one of the vulnerabilities requires that the output encoding is set to Shift_JIS. The vulnerabilities are reported in all versions prior to 2.1.5 and 3.1.1.
SOLUTION: Update to version 2.1.5 or 3.1.1.
PROVIDED AND/OR DISCOVERED BY: Reported by the vendor
Users of Nuke Evo should be aware that it use HTML Purifier 2.1.4 and should verify with the distribution vendors that this vulnerability does not affect them
Google Plans New Internet Measurement Tool
Posted On Wednesday, June 25, 2008 @ 05:40:22 CEST
in
Code-Authors
By
Guardian
nb1 writes: Google is expected to unveil on Tuesday a tool that measures Internet use to help advertisers identify the best places to buy ads that will reach their target audiences, according to a Wall Street Journal report.
The measurement tool, which will be offered free to advertisers and their agencies, will compete with services offered by established leaders Nielsen and ComScore. While those services base their estimations on selective surveys or customer panels, the newspaper said, Google's results will be based on data collected from Web servers, providing a deeper and broader picture of Internet behavior.
By giving away the new tool, Google could attract more advertising business. The announcement follows one last week about Google Trends' new service, which lets people type in specific domains and compare basic traffic information about any .com site using nothing more than organic user searches.
Included are daily traffic numbers in users (sent from Google search), where the users are coming from, and related sites that were either searched for or visited in that same session. After news of the planned tool hit the Web on Monday, ComScore shares fell $1.69, or 6.1 percent, to $26 after-hours trading. Nielsen is a privately owned company.
Silverchild track for Big Brother
Posted On Sunday, June 08, 2008 @ 07:19:16 CEST
in
Code-Authors
By
Guardian
Silverchild a UK indie/rock band who's website is hosted, sponsored and maintained exclusively by Code Authors is set to have one of their tracks feature in the UK's Big Brother TV Show. Silverchild have come a long way in the last year since their dedicated official fan site was launched by Code Authors and already have several tracks listed in the Top 10 Indie charts in America as well as getting air time on a number of internet radio and music sites.
Thanks to the hard work of the band, the growing legion of fans who promote their favourite Liverpool based band, Silverchild continue to go from strength to strength.
phpBB 2.x.x retires
Posted On Saturday, June 07, 2008 @ 18:48:02 CEST
in
Code-Authors
By
Guardian
On Wednesday 16th April phpBB announced their retirement plans for phpBB 2.0.x.
Commencing Wednesday 1st October 2008, phpBB 2.0.x download links will be removed from the download page at phpBB.com. Anyone wishing to obtain phpBB 2.0.x can continue to obtain the 2.0.x package at sourceforge.net.
Commencing Thursday 1st January 2009, phpBB 2.0.x will be formally retired, and support will no longer be actively provided for 2.0.x. Converting from 2.0.x to 3.0.x will continue to be supported.
Security patches, if required, will be provided until Sunday 1st February 2009.
The reason for the early retirement is the PHP Group's decision to retire PHP 4. phpBB 2.0 mainly runs on the PHP 4 codebase and it would be unwise to require people to have an unsupported version of PHP installed in order to use phpBB.
Ts Contact 1.0 Multilanguage
Posted On Tuesday, June 03, 2008 @ 12:00:39 CEST
in
phpNuke Themes
By
Guardian
queen_live78 writes: Ts Contact 1.0 Multilanguage is a new module for Php Nuke
Emails sent with CAPTHA protection. Help tips are available for all form fields. Email can be sent HTML format (with the sites logo).
Sender reports include Avatar and Nickname.
Note: Although this item was submitted translated into English from Italian, I have cleaned it up some more. I hope I got it right.
Lobo Links Free Submissions for Phpnuke Sites
Posted On Monday, June 02, 2008 @ 04:33:09 CEST
in
phpNuke Themes
By
Guardian
floppy writes: Lobo Links Web Directory is doing their free links for phpnuke sites again. Allowing anyone using the phpnuke cms to run their site to get a free regular listing in the directory. Its a great opportunity to start building your linking profile and help build some future page rank. All listings are permanent and free. You can't beat that!
Your submission requires a promotional coupon be inserted on the submission page. The promotional coupon code is freenukelinks. You will find the coupon field on the submission page at the very bottom. This coupon is for regular listings only.
This promotion is sponsored by RavenNuke and Clan Themes.