Sat, 19 Jan 2008 00:47:52 -0500 Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
Dan [Sat, 19 Jan 2008 00:47:52 -0500] rev 447
Not sure if $taboo was getting sanitized or not. Possibly an SQL injection vulnerability that allows maliciously crafted group names to inject SQL at a later date when the group CP is loaded. Unconfirmed, theoretical fix.
(0) -300 -100 -30 -10 -1 +1 +10 +30 +100 +300 tip