Andy Pieters napisał(a):
Is it possible for someone who does not have access to the server to edit arbitary accounts?
well this depends on the forum You use, there're many many exploits out there.
The best way to know is to try and keep up with places likethe bugtraq@xxxxxxxxxxxxxxxxx list, or other security websites/mailing lists and such.
-- Best wishes Łukasz -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php