asking users to disable is fair enough but no doubt the same doesn't apply to hacks which require file uploads as mentioned before.
I would rather, considering the mods are are aware of the issue, when sending out the email suggest a temp fix.
e.g. The vulnerability has been discovered for hack xx, in order to fix the the vulnerability please follow these steps (write steps) or disable the product and wait for the author to upload the fixed version.
I can understand it would not be possible if there are many locations within the code but if its only two or three, it isnt much work.
|