Hello folks. If you're running a Scoop site it would be worth your while to update from cvs, since we've just committed a patch to close a hole that allowed users to edit or submit new stories that appear to be written by any arbitrary other user. As far as I know, any site that allows users to write or edit any kind of story is affected by this. You can update from CVS following the usual directions, or, if that's inconvenient, you can simply apply the patch attached to this email. It's a pretty small fix, and won't monkey with anything else on the site. Just save the patch in your scoop root directory, and type: $] patch -p0 < aidbug.patch That should do it. --R (Here's hoping this list will allow me to send an attachment...) -------------- next part -------------- A non-text attachment was scrubbed... Name: aidbug.patch Type: text/x-patch Size: 1553 bytes Desc: not available Url : http://lists.kuro5hin.org/pipermail/scoop-help/attachments/20060726/913cdbee/aidbug.bin