jnorris Posted December 18, 2005 Posted December 18, 2005 Found @ nukecops.com This is a critical security flaw! I strongly advise at this time that ALL PHP-NUKE WEBSITES SHOULD DISABLE OFFSITE AVATARS! That is currently the easiest and fastest protection. If you currently have this feature enabled your website is at serious risk! I will not go into detail about how an exploit is possible at this time. I will not go into detail about how an exploit is possible at this time. Anyone who has seen the fix already knows how it is possible I would fix this immediately! you can turn off the off-site avatar function or apply the fix located here ---------> http://www.nukecops.com/postp207259.html#207259 Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.