How secure is the tiny mce wsiwyg? Is there any thing I can do to make it more secure from being hacked?
Version 1.3.8 latest version of tiny mce
Zen Cart Rocks!
thanks to all the hard workers out there
How secure is the tiny mce wsiwyg? Is there any thing I can do to make it more secure from being hacked?
Version 1.3.8 latest version of tiny mce
Zen Cart Rocks!
thanks to all the hard workers out there
I can't comment on its overall security, but I do know that one important thing to do for blocking abuse is to disable any file-upload capability used by any such editor/addon.
Perhaps others can comment on other matters related to its security.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donations always welcome: www.zen-cart.com/donate
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
You mean from the computer to the editor on the main screen/ezpage admin? That would make the editor not work to upload files from my computer or reference pics on the server?
Or in the php file system? where you could still load pics from the computer to the server and use them on the ez pages ect?
(referencing urls is kinda a pain)
Thanks for the reply! =)
Yes, I was referring to having the editor allow you to upload files via the editor screen while in your admin.
It's safer to use FTP to upload your own images, and simply refer to them in the HTML you write in your pages.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donations always welcome: www.zen-cart.com/donate
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
Bookmarks