there is a big vulnerability in this modification....my site was just hacked....THREE times.
this allows someone to place a code of script in the title of a post and it redirected my page...
even though there is this line of the fix:
v2.8 - Jul 08. 2006.
-Security bug fixed where some codes can be executed on site if entered as thread title. Upgrade
still didn't work. I ran the upgraded version since saturday, and today (tuesday), my site was hacked again. I disabled the hack, and the redirect went away, so I know it was related to this one.
Any fixes for this?
|