Antonio Chagoury wrote
Hmmm, SQL Injection.... now that is a big word. Have you tried exploiting that "possibility"? Nevermind, that is a retoric question, because SQL injections are not possible ATM with this module.
I am surprised that a person of your stature would just mock at a user reporting an injection problem.
I am not an expert, not a programmer so let me apologize if I said something wrong. As per my salesworthy understanding, if by substituting a parameter I can receive data that I am not supposed to (in this case on a different portal), an SQL injection attack succeeded. The Blog module does not validate if the EntryID being asked for belongs to the currently shown portal and it is a problem if I , as a host am charging $$$ from clients who have individual portals and have posted Blog Entries of their own. Nobody wants to see their content being shown under another Portal's logo, skin and design. Its a lawsuit waiting to happen for Dotnetnuke's paying customers.
<i> Also the reason I have not shown where this is happening </i>
As for the ability to change the ID... yes, you are correct, you can do that. Can you please add a ticket at http://support.dotnetnuke.com and reference this post?
I went to that page but how do I login there? My Dotnetnuke login does not work.
Thanks
Subodh