The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
I got this database error emailed to me today.
Quote:
The code in question is: PHP Code:
PHP Code:
Not sure what code is calling it with the bad error, but i don't really care, the field should be scrubbed anyways before it's passed to the query. Please comment |
#2
|
||||
|
||||
![]()
Users have no way to change the $userid variable passed into the function (as far as I'm aware), the only real exploit really is if someone made an addon where users could, or forcefully tried to exploit that function.
But, for stock vBulletin, it's perfectly safe ![]() - Zero Tolerance |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|