View Single Post
Old
  (#6 (permalink))
genoxide
Moderator
 
Status: Offline
Posts: 260
Join Date: Oct 2004
02-09-2005, 02:12 PM

A quick snippet and fix is to check if the $_POST came from this site and not from another, this way it can't be used like you said above.
I didn't say that is not a problem,i just said that is a problem easily fixed. But since fb doesn't listen to his community people are left alone with out any help from the original author.
I and a bud of mine which tends to be a security freak are working on my project (xero) and we are trying to make it as much secure as we can, if you are interested in testing,reporting,helping us just click on my sign.
   
Reply With Quote