Welcome!

Join our community of MMO enthusiasts and game developers! By registering, you'll gain access to discussions on the latest developments in MMO server files and collaborate with like-minded individuals. Join us today and unlock the potential of MMO server development!

Join Today!

Illumina CMS [PHP, OOP, MySQLi, Uber 3]

Status
Not open for further replies.
Junior Spellweaver
Joined
Jul 5, 2013
Messages
143
Reaction score
18
Uses the SMARTY template system and is fully MySQLi!! I also made the news articles use BBcode instead of HTML incase of malicious person trying to do <meta http-equiv="redirect" to send users to another hotel...

(bbcode is sent auto by the hk editor btw, no need for staff to remember it all)

Bans (done this morning actually lol)
User Ban:
IP Ban:
Ban appealed.. -
appeal responded to!!!

Whoever checks the ban now can decide to leave a message for the user, explaining the rejection maybe. If they don't want to respond, a generic response is left!

Goodjob with this Heju! When will it be released? anytime this week? Also can swift emu be used for it?
 
Newbie Spellweaver
Joined
Apr 25, 2013
Messages
33
Reaction score
9
Wrong. Hundreds of XSS based attacks can be carried out… still.

If you actually had any knowledge on exploits, you'd know that you can't gain access to a database carrying out XSS vulnerabilities. They're quite useless and the most they can do is edit a few things on your CMS.
 
I'm-a ruin you, punt!
Joined
Apr 6, 2008
Messages
575
Reaction score
193
If you actually had any knowledge on exploits, you'd know that you can't gain access to a database carrying out XSS vulnerabilities. They're quite useless and the most they can do is edit a few things on your CMS.

Are you a Special person? Who cares about the database!? As soon as you hijack a staff member’s session you have access to the housekeeping, I’ve used it hundreds of times on this very CMS. So pipe down you fool.

It’s obviously you who has zero understanding of exploits. “They're quite useless and the most they can do is edit a few things on your CMS.” – Hmm. So that’s why PayPal & Facebook consider them high risk exploits and actually pay people to report them? Because as you said all you can do is ‘edit a few things’ you complete idiot.
 
Last edited:
Newbie Spellweaver
Joined
Jun 1, 2013
Messages
8
Reaction score
4
If you actually had any knowledge on exploits, you'd know that you can't gain access to a database carrying out XSS vulnerabilities. They're quite useless and the most they can do is edit a few things on your CMS.
You're an idiot.

Using RFI, you could easily dump the contents of an entire database. Please know wtf you are talking about before spewing ignorant statements.
 
Status
Not open for further replies.
Back
Top