Author Topic: if you tested website optimiser before December 2010 and haven't removed it  (Read 3875 times)

Gurtie

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 1628
    • View Profile
just logged into a semi-abandoned account to find the message

Quote
mportant update to secure your site

If you have any experiments that you started before Dec. 3, 2010, you are using a control script that could allow an attacker to execute malicious code on your site. To fix the vulnerable section of code, you should immediately either replace the control scripts in your affected experiments or stop the affected experiments and start new experiments.

Experiments that use Website Optimizer code generated after Dec. 3, 2010, should not be susceptible to this type of attack.

In addition, even if a site is using code generated before Dec. 3, 2010, attackers can only execute malicious code on a website or browser if it has already been compromised by a separate attack. Though the immediate probability of this attack is low, we urge you to take action immediately.

so if you have a similar generally ignored account knocking around you might want to remove any out of date code!