There is a confirmed exploit with this hack allowing users to give themselves or someone else points and are able to define how much it would cost them at the same time.
Steps to recreate it;
Click the Donate to User button in the postbit, or from the main Ushop page
Type in your name or anothers username
instead of just a numerical value type in "1, uttpoints=99999"
1 will be the value in which it costs you to donate the points, and the 99999 are how many points you are giving them.
Does anyone know the way to only allow a numerical value in that textbox you type the points in?
|