« We have stuff for selling. ( us & eu base) Format : Track2 | Main | Remote Comments Schema »

Important Fast Search Security Update

A new version of the Fast Search plugin for Movable Type is available.

The new version is a very important security update, and I recommend that all sites install the new version as soon as possible.

The primary issue that has been fixed was a security bug in which a malicious person could insert HTML or javascript into your search results pages by modifying the query string. Please note that this does not affect regular user searches or tag searches, but rather search results pages that spammers have linked to from external web sites.

Other fixes include a pagination issue that was affecting certain users (in which the page numbers were inaccurate), and a fix for the tag_dir argument when the blog was not at the root off the domain.

You can download the new version from the links below:

Download Now

Fast Search 2.22 for MT4+:
Download Now
Downloads: 1124 (since 3/6/07)

Fast Search 2.092 for MT3.2 and 3.3:
Download Now
Downloads: 1124 (since 3/6/07)

If you have previously purchased the Pro version, you should have by now received an email with a download link. If not, please contact me.

Rate this entry:

  • Currently 3.9/5
  • 1
  • 2
  • 3
  • 4
  • 5
Rating: 3.9/5 (8 votes cast). Powered by the Ajax Rating plugin.

TrackBack

TrackBack URL for this entry:

Listed below are links to weblogs that reference Important Fast Search Security Update:

» همه چیز در رابطه با پلاگین Fast Search در مووبل تایپ 4.1x from مووبل تایپ فارسی
چرا از پلاگین Fast Search استفاده کنیم؟ مهمترین دلیلی که باعث استفاده از پلاگین Fast Search می شود این است که جستجوی موجود در مووبل تایپ فشار زیادی روی سرور می آورد و موجب مشکلاتی در سرور می شود. همچنین... [Read More]

» Change Log from Culture Snob
This page is the place where I'll post information about structure and feature changes at Culture Snob. In some cases, I'll also provide resources indicating how I did things. If you're having trouble with a particular feature, please report the... [Read More]

Comments (2)

arindam:

hi,
i just installed fast search on a couple of my blogs. using the dfault template. it does not appear to be picking up the MTSearchString variable. however it is seeing other mt tags such as the blogname etc.

any ideas why.

arindam:

if it helps, i did come across this mt4 dynamic publishing bug post http://mt-hacks.com/20071214-dynamic-publishing-bug-in-mt4.html

rebuilding mtview.php didnt help either.
how do i check to ensure dynamic publishing is working? could this be an issue with the server not allowing rewrites?

Post a comment

Gift idea: Buy Seinfeld DVD box set, complete 9 seasons!