Proving a security hole is quite easy, simply find where the SQL injection or code execution hole exists (bad eval, preg_replace with /e modifier etc.).
In previous cases of mods with issues the specific faulty code is reported to staff and the mod is put on hold.
Make sure you have hard proof, otherwise it is most likely that you were hacked via some other vector.
|