6 comments
Comment from: Ben borges
Comment from: fplanque
Latest developments:
- Versions 0.9.x are NOT affected. :)
- If your PHP (php.ini) is properly configured with register_globals = Off
, you are NOT affected. :)
- If your PHP (php.ini) is conservatively configured with allow_url_fopen = Off
, you are NOT affected either. :)
- We will release a fixed update of 1.x (version 1.8.6) later tonight.
In the meantime, if you are unsure, please delete the import-mt.php file.
Comment from: fplanque
Fixed releases (1.8.6 and 1.9.1) are ready (and downloadable from SourceForge if you’re in a hurry) but we’ll double check them tomorrow.
Comment from: edbennett
Thanks for the super-quick corrective actions!
Does this mean that you don’t need to delete the import-mt.php file in versions 1.9.2 onwards?
Comment from: fplanque
Yes versions 1.9.2 and above are perfectly safe. No need to touch mt-import in these.
Thanks ! :)