Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-14241

Security bug into Spambot control Questions

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Minor Minor
    • 3.1.9-RC1
    • 3.1.6
    • Other
    • None

      Spambots can avoid control question.
      phpbb/captcha/plugins/qa.php
      find

         function validate()
         {
            global $config, $db, $user;
       
            $error = '';
            
            if (!sizeof($this->question_ids))
            {
               return false;
            }
      

      Must change to

         function validate()
         {
            global $config;
       
            $error = '';
            
            if (!sizeof($this->question_ids))
            {
               $error = "Wrong question confirmation";
               return $error;
            }
      

            Marc Marc
            Boris Berdichevski Boris Berdichevski [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: