Quote:
Originally Posted by MrZeropage
@Pipo123:
the queries are fine, in one line of code the name is not cleaned, right, but the incoming name is pulled from the database, which means this is very hard or even not possible to use for an injection/exploit.
Anyway, the v2.6.8+ will be released in the next minutes having those queries changed to improve security
|
In fact it caused issues on our forums, that is how we found out the code was insecure.
The only thing to be done was to create a user with a bad username and visit the arcade to whipe the whole database or maybe worse: to make himself forum admin!