PDA

View Full Version : major security hole in uShop


FatalBreeze
07-22-2006, 07:38 AM
Hi guys, i've noticed that if im in the shop and uses this link:
.../ushop.php?do=richestusers&page=<script>alert("Owned%20By%20FatalBreeze")</script>

it works!!

maybe we should just add intval() or something like that?

as a noob coder im not exactly aware of the consequences this may have, but i guess they are pretty harsh.

btw, im using the latest version of uCash&uShop on vB 3.5.4.

Zachery
07-22-2006, 12:02 PM
uCS is no longer supported, or developed and we've already made refrences to move off of it.