Quote:
Originally Posted by stangger5
The security issue was s_id was allowed to be a string when it was supposed to be a int, that is what allowed the exploit.
Comments should be ok because of the way strings are put in the database.
|
Yeah, hence what I said he over corrected...
IMO, IBProArcade really needs a cleanup of the code one day...
Quote:
Originally Posted by gsmlover4u
there is nothing in arcade.php
|
If you haven't installed 2.7.2 there indeed is nothing.