NewsDaemon is a PHP based content management tool. It is designed to allow users to submit news and comment on stories. It is the tool used by DaemonNews for its Daily news site at http://daily.daemonnews.org.
Be the first to post a text review of NewsDaemon. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Due to security issues with the previous release that were recently exploited, a new version has been release to address these issue in addition to fixing other bugs and adding a few new features. See the CHANGELOG for details on the security issues with the previous versions.
Changes to v0.41 from v0.4 Note: Version 0.40 experienced a SQL injection vulnerability that was able to expose the nd_user table. While clear-text passwords are not stored in the database, it can expose personal information to an individual. The exact method of this exploit was never published, but a vulnerability was found during an audit involving improper validation of the LoginUser cookie. This vulnerability is believed to be fixed with this release. - SECURITY: Fixed possible SQL injection attacks per PHP sprintf and mysql_real_escape_string guidelines - SECURITY: Removed clear-text password information from the database as it wasn't being used anyway. - Fixed bug in nddaemon that caused it not to update the rdf status - Fixed bug in display of stories with comments in admin section. - Fixed bug in updating user fake email address from the admin page. - Added the navigation navbar to the database to make it usable by the user - Added ability to turn off nav bar display - Added start and stop date for new stories - Added creation date to the users table Changes to v0.4 from v0.31 - Added comment cache on stories to increase database efficency. - Added templates for story and date display. - Added Meta Keyword option to header. - Added option to display stories on a single line on the front page. - Fixed web looping problem with undeletable cookies. - Added a layout to the configuration screen to make options easier to find. - Added administrative comments to all stories so admins have a way to communicate. - Modified global admin permission system. You can now assign individual permissions. - Added user configuration option to select what topics you want to see. - Added user configuration option to add a signature to all comments. - Modified database to have indexes commonly used items to increase speed. - Added optional spell checking for all comments and stories. - Added optional mailing list support. - Login information will now be display even if navbar is turned off - Fixed problem with invalid hostname that would prevent admin from logging in. - Added a new user administration page. Will allow admin to disable accounts. - Added a daemon for controlling scheduled functions. - Added a Never Expire checkbox when logging in, for when you use a shared system. - Many minor bug fixes to numerous to mention.
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: