Okay, for those of you out there that use PHPNuke (not us thankfully), there is a rather large bug that allows anyone and everyone to access your password file directly through the browser. I'm not going to post it here because I know of too many sites that use the PHPNuke system. Instead, if you run one of these sites, please email me and I'll share the details with you. Please include the site that you work with in there also. Thanks to MarkL for sharing this with us!




