![]() |
Safe or not ??
Hi,
I was searching around for games for my arcade and stumbled upon a post suggesting this mod is subject to a SQLi error and it is one of the most exploited SQLi's ever oO !!! So is this true ? If so is there an exploit fix ? The post saying this was posted on 05-18-2013 and the last update for this mod was on 27 Feb 2012 so im a bit worried now .... |
I checked the source quickly (mainly the queries), but it seems safe.
addslashes is used at some places which is not safe if you use a certain character encoding, but I doubt anyone would ever use any of these character encodings for a vBulletin forum. |
I just sent you a pm of the warning post I found...
|
Quote:
|
Quote:
--------------- Added [DATE]1409690013[/DATE] at [TIME]1409690013[/TIME] --------------- So whats the verdict ? --------------- Added [DATE]1409691313[/DATE] at [TIME]1409691313[/TIME] --------------- im trying to reply to your PM but this site keeps timing out ? |
[quote=fookaa;2513538]Sent..
--------------- Added 02 Sep 2014 at 13:33 --------------- So whats the verdict ? Taking a quick look at version 2.7.2+, this should not be an issue, as they are now parsing the query string for SQL commands among other things. You should be using a PHP version of 3.5 or greater as a minimum. I will do some tests on it later this evening. :) |
What do you think about letting vBulletin Input Clean handle it ??
|
Any news on this ?
|
It's safe.
|
Definitely safe.
|
All times are GMT. The time now is 01:56 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|