in 0.7.4:
The blog entry title field seems prone to cross site scripting (XSS) attacks.
The blog/comment body text seems prone to XSS as well.
In the index.php script, the postid variable seems prone to SQL injection attacks.
jericho+bblog@attrition.org
Logged In: YES
user_id=1037458
Could you be a bit more elaborative on this matter?
Try and stick to the forum, irc, or flyspray, so that i
along with the others can see into this matter.
Thanks.