[Mageia-dev] A comparison of forum software from a security POV

Remco Rijnders remco at webconquest.com
Mon Sep 27 08:49:28 CEST 2010


On Mon, Sep 27, 2010 at 08:19:03AM +0200, Tux99 wrote:
> 
> I did a quick comparison of the most common forum software packages 
> (both commercial and FOSS) from a vulnerability point of view.
> 
> Here are the results, from most vulnerable to least:
> 
> grep -i phpbb sans-security_alert|wc -l
>     723
> grep -i vbulletin sans-security_alert|wc -l
>     256
> grep -i "Invision power board" sans-security_alert|wc -l
>     238
> grep -i mybb sans-security_alert|wc -l
>     176
> grep -i "Simple Machines Forum" sans-security_alert|wc -l
>      58
> grep -i fudforum sans-security_alert|wc -l
>       7
> 
> All I can say, I'm surprised that the official Mandriva forum (which 
> uses phpBB) is still standing... :-)
> 
> And this confirms another thing: FUDforum is really a hidden gem.

That, or newer and/or less popular and thus less used.

Thanks for doing this check though :)

Remco
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 197 bytes
Desc: Digital signature
URL: </pipermail/mageia-dev/attachments/20100927/b4c7cf34/attachment.asc>


More information about the Mageia-dev mailing list