Quote:
Today at 01:15 AM 97cobracpe said this in Post #79
Two php commands:
addslashes() and htmlspecialchars() were not used correctly with the intent of this hack. I noticed the same thing in the vbLink hack as well (which this was based off of).
I figured I help you out by posting my findings.
|
97cobracpe, thanks once again

Dont worry about stepping on my toes or anything, in fact I feel glad that some of you have stepped forward to help me along. I am very new to php and vb in general, nosedived into this hack purely cos i need something on this on my site and could not find any avail here yet.
For myself I too have removed all user submission code in my own installation at my site.
I prefer to have my own editorial team send me the stuff and i will load it up via admincp myself.
But personal preference I guess, at least this hack allows for more flexibility for those who prefer automated user submissions ( and via validation process )