Quote:
Originally posted by Karybdis
hi. W have your hack installed on the site I work at, but we've found a hole in the permission checking...
...Anyways, if you input an $avatcat value into the linking line.... like member.php?action=editavatar&avatcat=33, then it takes the user to that category even if they dont have the permissions for it. And apparently people have been passing this around our site for a long time, so it's becoming well known...
|
You are right. There really was the bug. This bug is eliminated since the version 1.25.1. You install the latest version 1.30 best

A couple of other bugs are also eliminated there