1
neoMJ
Re: CBB Team calling for members
  • 2005/5/23 17:50

  • neoMJ

  • Just popping in

  • Posts: 6

  • Since: 2005/4/25


A feature to merge and split topics would be great...



2
neoMJ
Re: Seems to be a security hole in 2.0.10! BIG!
  • 2005/4/25 22:17

  • neoMJ

  • Just popping in

  • Posts: 6

  • Since: 2005/4/25


Ok thank you very much!



3
neoMJ
Re: Seems to be a security hole in 2.0.10! BIG!
  • 2005/4/25 22:11

  • neoMJ

  • Just popping in

  • Posts: 6

  • Since: 2005/4/25


Yes it contains PHPSESSIONID...

I was suspecting that but I don't have much knowledge of that thing...

I don't have access to php.ini.

But I can create a ..htaccess file.

I wanna ask where should I create it? In which directory?



4
neoMJ
Seems to be a security hole in 2.0.10! BIG!
  • 2005/4/25 21:59

  • neoMJ

  • Just popping in

  • Posts: 6

  • Since: 2005/4/25


Ok guys, I guess we have a problem with 2.0.10 release...

I use default NewBB as a forum and my wholse XOOPS site is upgraded to 2.0.10..

Let me explain what happens:

When I send a link from a "private forum" topic to somebody who is not a member of my site, and when I am logged in at the moment, as soon as the other side clicks on the link he takes over my account! That means I got automatically logged out and he becomes logged in with my user name! Without entering a password! Just clicking on the link...

I don't wanna be exaggerating anything but that seems to be a serious bug! Can anybody look at it?




TopTop



Login

Who's Online

162 user(s) are online (125 user(s) are browsing Support Forums)


Members: 0


Guests: 162


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits