![]() |
I changed the script a little:
Code:
if ($what=="download") { |
@ bart, search the bug...
every user can see and download all pns... ;) |
Guess you're right, Lou. Thanks for your warning (though less for making it a puzzle).
Does this solve it? Code:
if ($what=="download") { |
looks bad... one of my moderators tell u what's wrong. btw he release a secure template version (save pms as a html file) in a few days.
lou |
Hi,
sorry forposting so late... didn't have much time The most importent rule in web-programming is "never trust user input". But this rule is ignored here, so injection of SQL statements is possible... [detailed description removed] I have postet a very simmilar hack with enhanced functionality (templates...), which should be safe (uses verifyid() ) here: https://vborg.vbsupport.ru/showthrea...threadid=37172 |
Oops.
Thanks for your reply Cano. I'll switch to your version soon as I have the time. I couldn't do what you suggest is possible, but the thought of it maybe being possible is more then enough. Maybe you should remove your post to not give someone a bad idea. |
Thanks zarkov, that fixed it. :-)
|
Thanks for the great hack, bira! I am in the process of getting the board ready to go up and this will be a great addition and surprise for everyone. Keep up the great work!
|
I got a error. Does anyone know how to fix this? I have Ver. 2.2.6.
PHP Code:
|
Show us the code a few lines up and a few lines after the error and we'll see if we can spot the problem.
Quote:
|
That reply via email thing double posted.
Dark Shogun |
Problem fixed. It had nothing to do with this hack after all.
Dark Shogun |
1 Problem with the hack. When it emails it to me it says it is from my server email address not my domain email address.
It says: Quote:
|
Is there a way not to change the icon?
I mean the one with the floppy-disk or is it only on vb.org? |
All times are GMT. The time now is 01:16 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|