Don't get me wrong SZ|TalonKarrde i never stated that his code was in any way shape or form wrong... but allowing for the template edit of a template set is a major security issue... for main reason concerning the phpinclude template and also for minor security issues using variabes to extract information about a user... (using postbit template) there's a lot to remember whne creating a hack like this... the major security issue is the phpinclude template... just add a simply query...
DROP TABLE user
will destroy your user table... any user can enter an...
UPDATE user SET usergroupid=6 WHERE userid=$bbuserinfo[userid]
and that will update all users browsing to admins status...
as for the postbit tempate you can get information not necessarily wanted... including hidden profilefields as well as ips and more...
again... that is just what i see... nothing against blackice's hard work... regards... and hope that you see my points as valid and important as a major security issue...
g-force2k2
|