Files
znc/modules
psychon bcb0306393 Don't allow users to change their user name through spoofed webadmin requests
Since adding and editing users is handled pretty much the same way in webadmin,
you could change your user name when you sent a POST requests with some
arbitrary user field:

 echo "user=newuser&submitted=1" | \
 lynx -post_data -auth=user:pass http://localhost:55455/edituser

This was spotted by SilverLeo who seems to spend quite some time trying to make
ZNC break, which is a good thing. Thanks!

Oh and btw, the last commit (delete the pid file) is from SilverLeo.
I forgot to mention him in the commit msg. Sorry.


git-svn-id: https://znc.svn.sourceforge.net/svnroot/znc/trunk@949 726aef4b-f618-498e-8847-2d620e286838
2008-02-10 10:18:54 +00:00
..
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2005-12-27 18:37:48 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00
2008-01-07 21:31:16 +00:00