Quote:
Originally Posted by MentaL
injection on arcade.php. Allowed a user to gain the MD5 and salt of any user it requested. best way to check if you are infected is to search for the following in your logs
Code:
Arcade&do=stats&comment=a&s_id=
If you find injection then follow it up.
|
For those not as tech minded it means a hacker could crack the password for any user on your site.
It would be a good idea to change the passwords of all admin accounts on your site if you had this mod installed.