View Single Post
  #1  
Old 5th October 2013, 13:21
joeroberts's Avatar
joeroberts joeroberts is offline
BT.Manager Owner
 
Join Date: Jan 2008
United States
Posts: 2,113
Default danger in the WHMCS code
any one using this code you are in danger of outsiders gaining access to you sites admin panel and all info in is.
this can be done from the basic users account by simply changing there name to a unsterilized text and it well change there name to all admins
username
email
password

Please watch you sites logs for users changing there names to a sql query.

I wont show the code that was used for safty resons but I have tested it on 2 Version
of the code and was able to retrieve both sites admin info.
__________________
Do not ask me to help you work on your site that is not phpMyBitTorrent
Do not ask me to make a mod for any other source
Do not Ask me to setup your site.
I will no longer help you setup your site, there is a setup script if you have trouble with it post in the forum here or in BT.Manager™ forum
My Current Demo is here http://demo.btmanager.org/
Reply With Quote