Dag Wieers wrote: >> Surely this is the responsibility of the drupal devteam and not the >> userbase to ensure stuff like this is not included. That specific >> module was at some time distributed from the drupal.org website wasent >> it ? > > Does the absense of such bug-reports make a solution more secure ? well, does a widely circulated known exploit that isnt going to get a fix instill confidence in you ? -- Karanbir Singh CentOS Project { http://www.centos.org/ } irc: z00dax, #centos at irc.freenode.net