WARNING - Security hole found in Pligg Send Announcement v0.2

Our friends over at Social CMS Buzz and given us a heads up on a new security issue. The module “Send Announcement v0.2″ was used on a Pligg install to send out spam emails to all the members.

There are no details as to how this happened, but it is for certain that this module was the culprit.

Social CMS, like I, are advising you to disable and remove this module until more details can be made available.



Related posts

Email campaigns and Pligg

Pligg 9.9.5 released

SocialCMSBuzz gets banned from the pligg forums for revealing PYcURL Security Vurnability

Pligg is Ajax unfriendly

Pligg Latest Submitted Story Module v0.1 Released



2 Comments »

  1. avatar comment-top

    Thanks for pointing this out. Security is no small issue.

    China Business Watchs last blog post..Not All Blogs Are Created Equal

    comment-bottom
  2. avatar comment-top

    Never ends when it comes to security and spammers.

    admins last blog post..Gold prices since 1988

    comment-bottom

RSS feed for comments on this post. TrackBack URL

Leave a comment