PDA

View Full Version : SQL hole , developer check this !!


Coverflow
11-24-2004, 07:31 AM
Yeah, white-hat on the wave here, I think I found an SQL injection hole at the download script... I tried this as the query and it worked

[thanks for notifying us, the problem will be taken care of asap: -Zafar]

I am not too good at this yet so I am not sure if it could be used for anything! If it really is something or you jsut wanna contact me you can add me to your MSN : mailto:coverflow@gmail.com or add me to MSN !!

Raistlin
11-24-2004, 08:02 PM
O.o
Ok. I don't know what that is!
Hopefully a mod will talk to Zafar.

Fungus
11-25-2004, 03:19 PM
ill talk to Zafar ASAP

Coverflow
11-25-2004, 04:11 PM
Hope you'll mail me

mail: coverflow@gmail.com

Fungus
11-26-2004, 12:49 AM
yes i will, after iv talked to Zafar the site admin.

imported_zafar
11-28-2004, 05:08 AM
Alright, Fungus IM'd me about it. There does seem to be a security issue, thanks for notifying us. I have emailed Nadeem (nkolia) who coded the script and I told him to email you about it. We should have this fixed asap. Also I'm gona remove the code from your post so that other people don't create more folders or someone possilbly does something malicious.