Exploit been found in MGC, My forum was nearly compromised because of this flaw. Luckily the hacker was testing, rather than destroying. I believe he's sent you an email, if you don't fix I will be pushing this forward to vBulletin staff.
Although if any vBulletin staff want to PM me and I'll explain how to re-inact the flaw, Which can I say gives out. username, salted password.
|