Quote:
Originally Posted by Digital Jedi
I guess it was useful for downloading individual tables, in addition to the CSV backup. But I don't think I've ever heard of anyone's site being compromised through that specific feature. I mean, once you have admin access, there's better ways into the server.
|
If you have only adminCP access, not really. It doesn't necessarily follow that those credentials get you into the server too.
I definitely agree with blind-eddie and you this was a major security flaw in v3.