Quote:
Originally Posted by liamwli
No, it doesn't. That code is only run if the username and password are correct.
Check the if statement at the top.
For this to work, someone would have to have a username that contained the SQLi.
|
????
go directly to liam_sll.php
if (($_POST['do'] == 'login') && ($vbulletin->options['liam_dualauth_onoff']))
set post 'do' to login