Users can delete any guestbook entries...
I tested now and it worksI can delete any guestbook entry just by changing the delete_id in the link when deleting my entries
Thats stupid! I was trying to make a fix... but I can't
I was looking for the source code of guestbook.php and I do not see any function that checks the owner of the entry :/
Any ideas?


LinkBack URL
About LinkBacks
Reply With Quote
Bookmarks