take a look at EditWarning pageEdit

Hi Nemphis,

Thanks for the great code done for EditWarning. You may take a look here Extension_talk:EditWarning, grab the french translation and maybe take a look at my problem.

Best regards, --Rmatt 00:46, 2 March 2009 (UTC)

Security IssueEdit

WARNING! This Extension lacks escaping of $user_id in EditWarning.class.php which might allow SQL injection. Since the author User:Nemesis has not given any contact information I decided to write this message right here. Details: An attacker may register hisself with a username like: '; DELETE * FROM ... -- The username will be passed into the query unescaped as soon as he starts editing a page. Contact me if you have any questions or need help: dergringo;AT:gmail(.)c0m


I followed the instructions for the 0.4 release and I am getting the following Notices:

Notice: Undefined index: wpSection in /data/wiki/extensions/EditWarning/EditWarning.php on line 79

Notice: Undefined variable: self in /data/wiki/extensions/EditWarning/EditWarningMsg.class.php on line 56

Notice: Trying to get property of non-object in /data/wiki/extensions/EditWarning/EditWarningMsg.class.php on line 56

Please help.

