Topic: New Exploit For PunBB v1.2.15
I found a Bug on PunBB... It is fatal. I want the fix... I can not post the Exploit, it is dangerous. ADMINS, contact me... dante90.dmc4@hotmail.it... Dante



Unfortunately no one can be told what PunBB is - you have to see it for yourself.
You are not logged in. Please login or register.
I found a Bug on PunBB... It is fatal. I want the fix... I can not post the Exploit, it is dangerous. ADMINS, contact me... dante90.dmc4@hotmail.it... Dante



Please read the description on this forum.. Click here <--- Click there to contact the admin ![]()
I've also sent you an email about this.
I do too, I'm still waiting for a reply ![]()
Just a heads up to people, I still haven't heard anything about this ![]()
[Dante: we know, I've talked to you about this -Smartys]
Last edited by Smartys (2007-11-18 20:52:08)



Dante, if you want to talk more about this with me, send me an email ![]()
Lets wait until there's a completely working version of 1.2.16? ![]()
But it was the Fix... O__O Dante



Which you posted prior to a working, official release. In other words, people wouldn't necessarily know to upgrade but the problem would still be disclosed.
Sorry I didnt mean to hassle. Thanks for the info smartys.
Oh, don't worry about it ![]()
The bug was this one: http://dev.punbb.org/changeset/1094
Basically, we didn't check the referrer when changing passwords. Not an issue for normal users, since they require the old password to be inputted, but admins/mods that can edit passwords would submit without an issue.
Thank you for the Thanks
I sent you an other email...
This time it isn't a dangerous Bug xD Dante



Powered by PunBB, supported by Informer Technologies, Inc.
Currently installed 5 official extensions. Copyright © 2003–2009 PunBB.