It finally happened. After nearly two years and 192,000 lines of code, ExpressionEngine got its first security bulletin. Damn.
This morning I was incredibly angry, not only at myself for letting something slip through, but also because when the exploit was found it was never brought to our attention. Instead, it was reported to a security site where not only was the information incorrect and misleading, but it was copied among other security sites without being confirmed. We only learned about it after a new member registered and mentioned it in the bug forum.
