Quote:
Originally Posted by Kier
I do not consider it to be a critical problem, as just about every web application out there can be exploited in this manner.
We are looking into ways to combat it for the forthcoming vBulletin release, but for now if you want a temporary fix and you are certain that your server sets the HTTP referer field, then you can use the code posted above.
|
call me a noob but how to test if server sets the HTTP referer field ?