Jump to content

Recommended Posts

Posted

The pager has now been re-enabled. Having gone through the source file and made a few changes, I'm now fairly confident of having plugged all previous security holes. If anyone experiences problems or oddities, please let me know.

Posted
:sadtears: :thumbsup:

Actually, I have an oddity: how can I still send and receive messages from a member who no longer exists? :)

Anders, is this? :(

In terms of retrieving messages for you, the pager doesn't rely on user data. If a message is being held for you in the system, it won't get deleted if its author unregisters. And I suppose you are still able to reply because there isn't a check in place which ensures the user you are replying to still exists.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...