Thank you for all of your efforts. This seems like a great product.
Quote:
Originally Posted by TyrbaneSilverha
I was really interested in using this mod, but I don't feel comfortable having a directory with PHP files in it that is CHMODed to 777. This smells of a security hole as anyone can modify those PHP files to display sensitive information. Is there a specific reason for vbactivity_type to be wide open?
|
I am also concerned about security. My site was recently exploited through the Post Thank You plugin by Abe1. A shell script was inserted into the ajax_complete.php.
I'm honestly not fluent enough to ask the right questions here, but have you had any experience with this product being similarly exploited? I'd really love to have a Thanks option again (members of my forum are begging for it) but not if it's going to leave me vulnerable to attack.
Thank you!