hi. W have your hack installed on the site I work at, but we've found a hole in the permission checking
dunno if this has been fixed before but I didnt notice it.. just point me to the right area please if it has ^^;;
Anyways, if you input an $avatcat value into the linking line.... like member.php?action=editavatar&avatcat=33, then it takes the user to that category even if they dont have the permissions for it. And apparently people have been passing this around our site for a long time, so it's becoming well known
just wanted to make sure this doesnt effect any other of the avatar permissions to and what changes could be made to the script to fix it.
had to disable our script in the meantime in case it effected anything else
thanks ^^;; Great hack btw ^^
|