Is SimplePHPBlog a secure blogging engine?

Posted by authentictech on Pro Webmasters See other posts from Pro Webmasters or by authentictech
Published on 2011-02-25T21:39:11Z Indexed on 2011/02/25 23:33 UTC
Read the original article Hit count: 334

Filed under:
|
|

Has anyone used the blog engine SimplePHPBlog? It is a simple blog engine that uses only text files (no database).

My problem with it is that the content directory where the texts files are stored appears to require being world writeable/readable (i.e. permission 777) for it to work. This means anyone can access the text files with a browser! These text files include the blog/comment poster's IP and email address!

This is not secure or good practice, right?

© Pro Webmasters or respective owner

Related posts about security

Related posts about blog