Hi,
won't ban you. I think the order you take with hacking the site and than informing us is not right.
I think I fixed it. If I remember right and if it's the same security hole, I fixed it after we heared about it but after the change of servers forgot it.
Can you test it De Gris?
Cheers, Ingo
Yeah, you fixed the LFI. Still, some other thing you might want to fix;
-Your SQL DB is remotely accessible. Unless you have a really good reason for that, turn that off. Even with the login data I got from the LFI I wouldn't have been able to do shit without the SQL DB.
-Your press/media logins in the database aren't hashed, and since they have an upload form, you might want to hash those.