<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Topic: TimThumb security issue</title>
		<link>http://www.kriesi.at/support/topic/timthumb-security-issue</link>
		<description>Support Forum - Topic: TimThumb security issue</description>
		<language>en-US</language>
		<pubDate>Fri, 24 May 2013 07:34:50 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/topic/timthumb-security-issue" rel="self" type="application/rss+xml" />

		<item>
			<title>Chris Beard on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-32357</link>
			<pubDate>Fri, 18 Nov 2011 18:46:11 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">32357@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;The current version of the theme doesn't bring up any issues regarding the timthumb integration. If it does for you, could you specify what the problem is exactly?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>robdobson on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-32315</link>
			<pubDate>Fri, 18 Nov 2011 14:28:29 +0000</pubDate>
			<dc:creator>robdobson</dc:creator>
			<guid isPermaLink="false">32315@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;No it wasn't. And still isn't. I quote from above...&#60;/p&#62;
&#60;p&#62;&#34;Yes - I checked my levitation copy and Kriesi forgot to update the script. I'll notify him to release an updated version asap.&#34;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kriesi on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-31045</link>
			<pubDate>Thu, 03 Nov 2011 03:01:38 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">31045@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey! &#60;/p&#62;
&#60;p&#62; Hey! yes the theme was updated a while ago with the latest version of timthumb ;) &#60;/p&#62;
&#60;p&#62; Regards,&#60;br /&#62;
Kriesi
&#60;/p&#62;</description>
		</item>
		<item>
			<title>breakpoint on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-31005</link>
			<pubDate>Wed, 02 Nov 2011 12:12:07 +0000</pubDate>
			<dc:creator>breakpoint</dc:creator>
			<guid isPermaLink="false">31005@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Is Kriesi on holiday? :)
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Beard on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-30731</link>
			<pubDate>Sun, 30 Oct 2011 02:29:11 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">30731@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;You can edit the timthumb.php file to be like&#60;a href=&#34;http://timthumb.googlecode.com/svn/trunk/timthumb.php&#34;&#62;this&#60;/a&#62;, this should solve the security issue though I'm uncertain if any other adjustments need to be made to function correctly with the Levitation theme.&#60;br /&#62;
I'll check with Kriesi.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>breakpoint on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-30681</link>
			<pubDate>Fri, 28 Oct 2011 11:41:46 +0000</pubDate>
			<dc:creator>breakpoint</dc:creator>
			<guid isPermaLink="false">30681@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Dude, has the Timthumb issue been corrected for the Levitation theme?  I'd like to purchase it ASAP, but will wait until the fix is in place.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Dude on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-29337</link>
			<pubDate>Wed, 12 Oct 2011 16:25:43 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">29337@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Yes - I'll post a notification here :)
&#60;/p&#62;</description>
		</item>
		<item>
			<title>robdobson on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-29309</link>
			<pubDate>Wed, 12 Oct 2011 09:09:12 +0000</pubDate>
			<dc:creator>robdobson</dc:creator>
			<guid isPermaLink="false">29309@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Thank you. Could you post here please when it is available at ThemeForest.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Dude on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-29294</link>
			<pubDate>Wed, 12 Oct 2011 07:24:30 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">29294@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Yes - I checked my levitation copy and Kriesi forgot to update the script. I'll notify him to release an updated version asap.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>robdobson on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-29241</link>
			<pubDate>Tue, 11 Oct 2011 19:15:31 +0000</pubDate>
			<dc:creator>robdobson</dc:creator>
			<guid isPermaLink="false">29241@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi, in the version.rtf file of 1.3.2 it says...&#60;br /&#62;
&#34;file: framework/includes/timthumb.php : updated file for security reasons to latest version&#34;&#60;/p&#62;
&#60;p&#62;But I don't understand what this means. There is no files in levitation/includes when I extract the zip.&#60;br /&#62;
'includes' is just an empty folder that wasn't there in the previous version of the theme.&#60;br /&#62;
And levitation/timthumb.php is exactly the same as before.&#60;/p&#62;
&#60;p&#62;I don't understand what's been updated. Can you explain it please.&#60;/p&#62;
&#60;p&#62;Thanks.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Dude on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-24618</link>
			<pubDate>Thu, 11 Aug 2011 16:32:01 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">24618@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey,&#60;br /&#62;
Kriesi already works on updates. There's no need to panic though because hacker can find better targets than private or small business sites.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>robdobson on "TimThumb security issue"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-security-issue#post-24615</link>
			<pubDate>Thu, 11 Aug 2011 16:26:11 +0000</pubDate>
			<dc:creator>robdobson</dc:creator>
			<guid isPermaLink="false">24615@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;I see someone mentioned about this in the Avisio forum but I have two sites using the Levitation theme.&#60;/p&#62;
&#60;p&#62;Firstly, if Auto Scaling is off in the Theme Options is it safe to delete the script completely and save any further problems? Or maybe just empty the file as you suggested in the Avisio forum but keep the file in place.&#60;/p&#62;
&#60;p&#62;But if Auto Scaling is on how do I go about updating the script for the Levitation theme? I tried to replace the code in timthumb.php with the new version of this script but it didn't work.&#60;/p&#62;
&#60;p&#62;Thanks in advance.
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
