Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Fixes by NY
#8
NY: I am curious as to why this is a security hole? All it does is takes the $_GET['id'] variable and looks for a file with the same slug. If it doesn't get an ID, it goes to the homepage, and if it gets an ID that doesn't exist it throws up a 404.

To me this doesn't sound like a security hole at all.


Also, in your first post I agree with Zegnat that i like the username check the way it is. As for the cookie function, this function is changed around in version 2.0, and wont be used quite like that anymore.
- Chris
Thanks for using GetSimple! - Download

Please do not email me directly for help regarding GetSimple. Please post all your questions/problems in the forum!
Reply


Messages In This Thread
Fixes by NY - by Nijikokun - 2010-01-08, 03:13:48
Fixes by NY - by Nijikokun - 2010-01-08, 03:28:01
Fixes by NY - by Nijikokun - 2010-01-08, 03:35:04
Fixes by NY - by Nijikokun - 2010-01-08, 04:10:01
Fixes by NY - by Zegnåt - 2010-01-08, 05:29:27
Fixes by NY - by Nijikokun - 2010-01-08, 06:00:08
Fixes by NY - by Nijikokun - 2010-01-08, 06:32:37
Fixes by NY - by ccagle8 - 2010-01-08, 11:41:47
Fixes by NY - by ccagle8 - 2010-01-08, 11:44:19
Fixes by NY - by Nijikokun - 2010-01-08, 12:59:43
Fixes by NY - by Zegnåt - 2010-01-08, 19:48:27
Fixes by NY - by Nijikokun - 2010-01-09, 02:53:56



Users browsing this thread: 2 Guest(s)