Quote:
Originally Posted by Zachery
Are you 100% positive your running the .95a files?
I am fairlay sure we fixed this problem.
|
I am 100% certain this is a problem in .95a. I just re-downloaded it and put it on my site to verify.
The problem is NOT that the user can donate to themselves, but rather can put a very simple string into the "How much would you like to donate?" field and give themselves (or anyone) many more points than it should send.
For obvious reasons I won't post how here, but I will PM Zachary with details. The simple fix I mentioned in my previous post patches this major exploit.