FUDforum
Fast Uncompromising Discussions. FUDforum will get your users talking.

Home » FUDforum Development » Bug Reports » Icon bug.
Show: Today's Messages :: Polls :: Message Navigator
Return to the default flat view Create a new topic Submit Reply
Re: SQL buggy. [message #13953 is a reply to message #13945] Sat, 01 November 2003 19:05 Go to previous messageGo to previous message
Ilia is currently offline  Ilia   Canada
Messages: 13241
Registered: January 2002
Karma:
Senior Member
Administrator
Core Developer
Xodnizel wrote on Sat, 01 November 2003 12:35

In 2.5.3RC3, at least, there is a *sql insertion bug in the merge thread(and probably split thread, as well) feature.

The problem is in the handling of the sel_th[] form element.

I don't know if it's exploitable or not, but you'd need to be a moderator(or an admin, but that's sort of pointless then) to see the bug.


Addressed. Mind you it is even if you were to inject some stuff into MySQL nothing would happen. And like you said you'd need to be a priveledged user already.


FUDforum Core Developer
[Message index]
 
Read Message
Read Message
Read Message
Read Message icon10.gif
Read Message " alt="icon10.gif">" />
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: Cant login!!
Next Topic: Broken Links with pathinfo 2.6.0RC2
Goto Forum:
  

-=] Back to Top [=-
[ Syndicate this forum (XML) ] [ RSS ]

Current Time: Thu Nov 28 05:56:53 GMT 2024

Total time taken to generate the page: 0.05038 seconds