..especially with a forum software that lets you send raw SQL calls through a HTML tag. I read a nice security paper written specifically about how to exploit a server running wwwthreads, since it requires a mySQL (or equivelant) server running to store the forum data on.
I was just over at the wwwthreads web page, looking at the changelog.. noticed one of the upgrades was specifically a security upgrade, and it was fairly recent.. So they might have patched THOSE perticular problems up..
-mark


...proud to have one of the first Mark I units
_________________________
http://mvgals.net - clublife, revisited.