1.3.1 Security Patch

Jul 7, 2008 at 11:48 AM
I am trying to find the 1.3.1 security patch for BlogEngine 1.3 but the link given on the main site (http://dotnetblogengine.net/file.axd?file=BlogEngine1.3.1Patch.zip) doesn't appear to work anymore and I couldn't track the file or the relevant changes down on the CodePlex site.

Could someone point me in the right direction?

Thanks.

Andrew
Jul 7, 2008 at 12:08 PM
Edited Jul 7, 2008 at 12:09 PM


andrewescrivo wrote:
I am trying to find the 1.3.1 security patch for BlogEngine 1.3 but the link given on the main site (http://dotnetblogengine.net/file.axd?file=BlogEngine1.3.1Patch.zip) doesn't appear to work anymore and I couldn't track the file or the relevant changes down on the CodePlex site.

Could someone point me in the right direction?

Thanks.

Andrew


Hi Andrew,
I've tried the link and it works fine, so try it again. Tell me if it persist to fail and I will send it to you by mail.
Jul 7, 2008 at 12:33 PM
Hi,

How strange - that link really does not work for me! I tried both Firefox and IE7...

I've sent you a message with my email address - if you could forward the file to me that would be great.

Thanks

Andrew
Jul 7, 2008 at 4:38 PM
Thanks to nmgomes for emailing the file through to me - but unfortunately what I really wanted was the source changes that occurred in order to fix this security issue, because I want to apply them to a site that was based on the BlogEngine Photo Gallery which now unfortunately appears to be a dead project.

I have eventually managed to work out the relevant source code changes by using the instructions for connecting via TortoiseSVN as there didn't seem to be a way to see the difference between two different changesets via the CodePlex web interface? (Changeset 10853 from Apr 13 was when the security issue was fixed)

Will I have resolved the security issue if I just apply these straightforward changes from changeset 10853?

With thanks.

Andrew