I've been beating my head against a wall trying to figure out a small but still potentially serious security issue that's tied to PHP and uploading.
On the brighter side of things, I've run dozens of XSS tests on the comment and mail forms and have found zero security holes there which is a big relief. I've also spent a fair amount of time with the search feature and the site's page-handling in general and all results have been positive.
»
Read more...