This vulnerability came into notice when in installed phpfreechat and a hacker tried to hack my site...

the link to the php free chat is http://poemsnprose.com/livechat . A hacker became a member and then used http://poemsnprose.com/livechat?destination=node%2F381 or http://poemsnprose.com/livechat?destination=node%2F[any other number]... what do u know? it opened up a similar independent chat page... this is a MOJOR vulnerability and MUST be stopped.

Can anyone help. I did post other issues in the site but non got even one response... is that not funny? :)) and i'll be surprised if this issue is ever even addressed...

Amartya Ray

Comments

dave reid’s picture

Project: Drupal core » phpFreeChat integration
Version: 6.10 » 6.x-1.x-dev
Component: file system » Code

Moving to proper issue queue.