Previous Thread
Next Thread
Print Thread
Hop To
Joined: Jun 2006
Posts: 106
member
member
Joined: Jun 2006
Posts: 106
I run a tight ship on user uploaded avatars due to problems long ago with people using bad avatars. I turned on the stock avatars just because a couple people bothered me to death about it.

Anyhow one of my users says:

"it's quite easy to come around the system and use your own image for the avatar.
I just used Web-developer toolbar in firefox to show the hidden edit fields and I could then edit it's contents and submit the form."

Last edited by Rick; 11/08/2006 1:16 PM.
Flyin V #167888 11/07/2006 1:02 PM
Joined: Jul 2006
Posts: 3
J
stranger
stranger
J Offline
Joined: Jul 2006
Posts: 3
I can confirm this bug.

I see no reference to ALLOW_REMOTE_AVATARS in changebasic.inc.php and no proper checks in newuser.inc.php. The only references I can find where the value ALLOW_REMOTE_AVATARS is checked is to determine whether or not to display the HTML.

Joshtek #167889 11/07/2006 1:11 PM
Joined: Jun 2006
Posts: 9,242
Likes: 1
R
Former Developer
Former Developer
R Offline
Joined: Jun 2006
Posts: 9,242
Likes: 1
Yeah, need to put in a check to make sure the specified URL is local if remove avatars isn't turned on. Will get that fixed for 7.0.2.

Rick #167892 11/07/2006 2:03 PM
Joined: Jul 2006
Posts: 3
J
stranger
stranger
J Offline
Joined: Jul 2006
Posts: 3
Cheers. Maybe remote avatars should always be okay if set by admins/mods through doprofiles.php, tho.


Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Mirrored databases
by Baldeagle - 12/05/2025 3:27 PM
Cant get past check files during upgrade
by sniperbbb - 11/27/2025 1:55 AM
UBB.threads 8.0.1 Patch Released: Fixes
by isaac - 11/26/2025 1:39 PM
8.0.1 Patch Changelog Discussion
by isaac - 11/26/2025 12:34 PM
Who's Online Now
0 members (), 3,240 guests, and 216 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
test
test
by Gizmo, August 20
Ride safe!
Ride safe!
by Morgan, December 7
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Powered by UBB.threads™ PHP Forum Software 8.1.0
(Snapshot build 20251126)