<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Ajax Edit Comments now with Move Comments feature</title>
	<atom:link href="http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/feed/" rel="self" type="application/rss+xml" />
	<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/</link>
	<description>Blogging, WordPress, Work and Life</description>
	<lastBuildDate>Fri, 03 Feb 2012 04:38:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Rene</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5928</link>
		<dc:creator>Rene</dc:creator>
		<pubDate>Tue, 29 Sep 2009 17:30:07 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5928</guid>
		<description>fixed now... good to know. nice! as i pointed out in my post, rejecting bogus action parameters would be best practice. better than just sanitizing.</description>
		<content:encoded><![CDATA[<p>fixed now&#8230; good to know. nice! as i pointed out in my post, rejecting bogus action parameters would be best practice. better than just sanitizing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5927</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Tue, 29 Sep 2009 17:25:35 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5927</guid>
		<description>Should be fixed now!

However, thanks to you pointing this out, Ronald and me are working on making this even more secure.</description>
		<content:encoded><![CDATA[<p>Should be fixed now!</p>
<p>However, thanks to you pointing this out, Ronald and me are working on making this even more secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rene</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5926</link>
		<dc:creator>Rene</dc:creator>
		<pubDate>Tue, 29 Sep 2009 17:22:58 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5926</guid>
		<description>Your site is still vulnerable: ttp://ajaydsouza.com/wp-content/plugins/wp-ajax-edit-comments/php/move-comment.php?action=%22%3E%3C/input%3E%3Cdiv%20style=position:absolute;top:0;left:0;width:2000px;height:1000px;background-color:black;font-size:120px;color:red;%3ETHIS%20SHOULD%20NOT%20BE%3Cbr%3EPOSSIBLE%3C/div%3E%3Cspan%20style=color:black%3E%3Cinput%20type=%22hidden

let me suggest you update to the version you just have released... lmao</description>
		<content:encoded><![CDATA[<p>Your site is still vulnerable: ttp://ajaydsouza.com/wp-content/plugins/wp-ajax-edit-comments/php/move-comment.php?action=%22%3E%3C/input%3E%3Cdiv%20style=position:absolute;top:0;left:0;width:2000px;height:1000px;background-color:black;font-size:120px;color:red;%3ETHIS%20SHOULD%20NOT%20BE%3Cbr%3EPOSSIBLE%3C/div%3E%3Cspan%20style=color:black%3E%3Cinput%20type=%22hidden</p>
<p>let me suggest you update to the version you just have released&#8230; lmao</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5925</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Tue, 29 Sep 2009 15:47:45 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5925</guid>
		<description>The latest version should fix those vulnerabilities</description>
		<content:encoded><![CDATA[<p>The latest version should fix those vulnerabilities</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kestrel</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5924</link>
		<dc:creator>kestrel</dc:creator>
		<pubDate>Tue, 29 Sep 2009 14:11:27 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5924</guid>
		<description>Guys - thanks so much for the quick fix. Sounds like there may be an additional vulnerability in wp-ajax-edit-comments?

It&#039;s too bad WP doesn&#039;t have an &quot;urgent plugin update&quot; function that puts a notification at the top of the admin page (or maybe it does??). I&#039;m sure this kind of thing happens a lot with other plugins.</description>
		<content:encoded><![CDATA[<p>Guys &#8211; thanks so much for the quick fix. Sounds like there may be an additional vulnerability in wp-ajax-edit-comments?</p>
<p>It&#8217;s too bad WP doesn&#8217;t have an &#8220;urgent plugin update&#8221; function that puts a notification at the top of the admin page (or maybe it does??). I&#8217;m sure this kind of thing happens a lot with other plugins.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rene</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5921</link>
		<dc:creator>Rene</dc:creator>
		<pubDate>Tue, 29 Sep 2009 05:25:06 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5921</guid>
		<description>Do yourself a favor and fix your wp-ajax-edit-comments too. Wouldnt be bad if you were a little more communicative about this issue and WARN those who have installed it as well.</description>
		<content:encoded><![CDATA[<p>Do yourself a favor and fix your wp-ajax-edit-comments too. Wouldnt be bad if you were a little more communicative about this issue and WARN those who have installed it as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5920</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Tue, 29 Sep 2009 01:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5920</guid>
		<description>It&#039;s been fixed and the new version 2.4.0.3 has been uploaded</description>
		<content:encoded><![CDATA[<p>It&#8217;s been fixed and the new version 2.4.0.3 has been uploaded</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rene</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5919</link>
		<dc:creator>Rene</dc:creator>
		<pubDate>Mon, 28 Sep 2009 17:56:33 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5919</guid>
		<description>Ajay you gotta fix this:

---</description>
		<content:encoded><![CDATA[<p>Ajay you gotta fix this:</p>
<p>&#8212;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kestrel</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5909</link>
		<dc:creator>kestrel</dc:creator>
		<pubDate>Tue, 22 Sep 2009 03:10:45 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5909</guid>
		<description>thanks!! also to clarify, actually you only get the &quot;request failed&quot; error if the comment is in need of moderation. if an unregistered user is &quot;trusted&quot; and the post is automatically approved, you get the other situation (post disappears without &quot;success&quot; message, leaving user wondering exactly what happened). 

Anyway thanks to you and Ronald for this plugin which is becoming more useful at light speed and in unexpected ways!</description>
		<content:encoded><![CDATA[<p>thanks!! also to clarify, actually you only get the &#8220;request failed&#8221; error if the comment is in need of moderation. if an unregistered user is &#8220;trusted&#8221; and the post is automatically approved, you get the other situation (post disappears without &#8220;success&#8221; message, leaving user wondering exactly what happened). </p>
<p>Anyway thanks to you and Ronald for this plugin which is becoming more useful at light speed and in unexpected ways!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://ajaydsouza.com/archives/2009/09/19/ajax-edit-comments-now-with-move-comments-feature/#comment-5908</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Tue, 22 Sep 2009 02:44:38 +0000</pubDate>
		<guid isPermaLink="false">http://ajaydsouza.com/?p=1812#comment-5908</guid>
		<description>Hi Kestrel,

When a user requests removal, the comment moves to the moderated queue, hence the &quot;request failed&quot;.

But, yes it can be worded better.

I&#039;ll pass this on to Ronald and look into it myself. We can try implementing some of the suggestions above.</description>
		<content:encoded><![CDATA[<p>Hi Kestrel,</p>
<p>When a user requests removal, the comment moves to the moderated queue, hence the &#8220;request failed&#8221;.</p>
<p>But, yes it can be worded better.</p>
<p>I&#8217;ll pass this on to Ronald and look into it myself. We can try implementing some of the suggestions above.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

