Live Demo: http://chxo.com/feedsplitter/index.php
Download: get the lastest from here
Security Alert: This is release is a critical upgrade.
There is an interactive demo online.
You can install feedsplitter on any PHP-enabled web server (v4 or better). It should work with most shared webhosts. See the Feedsplitter Homepage for download information.
Oct 29, 2006:
Sep 19, 2006:this post. I'm sorry this took so long to fix, the author was unable to contact me (or didn't try), and I don't follow bugtraq closely. Please click through for details and new code.
This release fixes a damned embarassing directory traversal exploit, whereby an attacker could potentially read any .xml file readable by the webserver user, if they know the exact path.
This release also fixes a potential cross-site scripting exploit.
This release also removes a situation where an attacker could potentially inject php code into the RSS feed. I wasn't able to get this exploit to work, but the potential had to be addressed. This release does not eval() any part of the feed, ever.
Finally, I added a built in test feed to prove that php and xss attacks cannot be embedded in feeds. I heartily welcome any additional tests, please let me know.
If you haven't already "subscribed to this folder" you should. There will be updates, and you'll want to get an email.
The tarball is here: feedsplitter-2006-09-19.tar.gz
Again, you MUST UPDATE your feedsplitter installation, or stop using it. I apologize, profusely, for the inconvenience.
Jan 21, 2006:
Download the tarball here: feedsplitter-2006-01-21.tar.gz.
Feb 19, 2004:
- Unicode characters in feeds are now handled correctly
- Feedsplitter sends appropriate HTTP cache headers, MUCH more efficient
- Configuration has been moved to a separate file, and local configuration won't be overwritten by upgrades.
- A configuration value ($hosts_allowed) allows you to restrict feedsplitter use to pages on your website.
The source tarball is here
If you're looking for the install file it's in the next version. Thanks for the feedback, y'all. Pay me next time.
Many thanks to Scott McDowell, Edward Spodick, and Peter Scott for their suggestions and patches!
See "more" to download.
Jun 13, 2003:Berylium2. In fact, Feedsplitter.php will become the official newsfeed rendering engine for all Berylium sites.
Jan 31, 2003:
Jan 28, 2003:
This is the last page of Feedsplitter.