Quote:
Originally Posted by FrOgZ
Oh yes, Zach: I also got this email:
Database error in vBulletin 3.0.1:
Invalid SQL: UPDATE user SET uttpoints=uttpoints+??e631000000000000000000000000 00000000000000000000000000000000000000000000000000 00 >1 WHERE userid='249'
mysql error: You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near '??e6310000000000000000000000000000000000000000000 00000000000000
mysql error number: 1064
...I hope this is help
|
Looks like someone found a loophole in a script somewhere, and they're executing SQL through it. Be glad they're not doing a "DROP TABLE `post`" or anything like that.