Thread: YSE v2.0 PRE6
View Single Post
  #9  
Old 30th July 2009, 10:53
kp380lv's Avatar
kp380lv kp380lv is offline
Senior Member
 
Join Date: May 2008
Latvia
Posts: 388
Default
Are you sure?

details.php

PHP Code:
$id $_GET["id"]; 
should be:

PHP Code:
$id = (int) $_GET["id"]; 
So there is security vulnerabilities...

Or better change this to:

PHP Code:
if (!is_valid_id($_GET['id']))             stderr($tracker_lang['error'], $tracker_lang['invalid_id']);
$id = (int) $_GET["id"];