<?xml version="1.0" encoding="UTF-8"?>
<issue>
  <id>464</id>
  <project name="MyBB" id="1"/>
  <tracker name="Bug" id="1"/>
  <status name="Closed" id="5"/>
  <priority name="Immediate" id="7"/>
  <author name="Ryan Gordon" id="8"/>
  <assigned_to name="Ryan Gordon" id="8"/>
  <category name="Security Issue" id="12"/>
  <fixed_version name="1.4.9" id="17"/>
  <subject>Invalid avatar extensions</subject>
  <description>There is an SQL Injection vulnerability in avatar extension checking &amp; validating. You are able to bypass it with a specially crafted filename.</description>
  <start_date>2009-09-20</start_date>
  <due_date></due_date>
  <done_ratio>100</done_ratio>
  <estimated_hours></estimated_hours>
  <custom_fields>
    <custom_field name="Reproducibility" id="4">Always</custom_field>
    <custom_field name="Reported In MyBB Version" id="2">1.4.8</custom_field>
    <custom_field name="PHP Version" id="3"></custom_field>
    <custom_field name="Browser" id="7"></custom_field>
    <custom_field name="Database Type" id="5"></custom_field>
    <custom_field name="Database Version" id="6"></custom_field>
  </custom_fields>
  <created_on>Sun Sep 20 21:27:16 -0500 2009</created_on>
  <updated_on>Mon Sep 21 01:21:50 -0500 2009</updated_on>
  <journals>
    <journal id="1495">
      <user name="Ryan Gordon" id="8"/>
      <notes></notes>
      <details>
        <detail property="attr" old="8" name="project_id" new="1"/>
      </details>
    </journal>
    <journal id="1498">
      <user name="Ryan Gordon" id="8"/>
      <notes></notes>
      <details>
        <detail property="attr" old="" name="category_id" new="12"/>
        <detail property="attr" old="" name="fixed_version_id" new="17"/>
      </details>
    </journal>
    <journal id="1501">
      <user name="Ryan Gordon" id="8"/>
      <notes>Applied in changeset r4458</notes>
      <details>
        <detail property="attr" old="0" name="done_ratio" new="100"/>
      </details>
    </journal>
    <journal id="1503">
      <user name="Ryan Gordon" id="8"/>
      <notes></notes>
      <details>
        <detail property="attr" old="7" name="status_id" new="5"/>
      </details>
    </journal>
  </journals>
</issue>
