Re: Simple Machine Forum - Private section/posts/info disclosure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



At 14:40 8.11.2007, h3llcode@xxxxxxxxxx wrote:
# In my forum i've a Staff area , and into that , there is a message that contain Bug,exploit or some others keywords...i'll put in the advanced search module # this keywords ,and i select "show results as messages"...and tadaaa...my priv8 zone can be read by everyone...

Logged in my forum as an admin.
Went into private section, found some unique keyword.
Had it searched in advanced search, it was found (as expected)

Logged off.
Had it searched in advanced search, not found (as expected)

What's your point then?


Jindrich Kubec <kubecj@xxxxxxxxx>


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux