There are several exploits that members have found on how to exploit with the script.
1. They have discovered that all they have to do is change the number in the adopt link (from adopt.php?id=xx) as a shortcut to getting any adoptable they want. They can even change this in this link "/doadopt.php?name=&id=28&promocode=&Submit=Adopt+Me" to get the different adoptables.
2. Refreshing the adoption page by either pressing the refresh button or ctrl+F5 to mass adopt as many as they want....
My suggestions are, some kind of mod (maybe a javascript mod) that hides the adoption link in the the status bar and the actual address bar so that they just see adopt.php and nothing to do with the id number. I have tried several different javascript mods to hide the the links from appearing, but they dont work with the latest versions of Firefox and IE.
And secondly some kind of a check that means after 1 adoptable has been adopted, the member is either taken directly to their profile page or if they do decide to refresh the page, the refresh sends them back to the main adoption page.
1. They have discovered that all they have to do is change the number in the adopt link (from adopt.php?id=xx) as a shortcut to getting any adoptable they want. They can even change this in this link "/doadopt.php?name=&id=28&promocode=&Submit=Adopt+Me" to get the different adoptables.
2. Refreshing the adoption page by either pressing the refresh button or ctrl+F5 to mass adopt as many as they want....
My suggestions are, some kind of mod (maybe a javascript mod) that hides the adoption link in the the status bar and the actual address bar so that they just see adopt.php and nothing to do with the id number. I have tried several different javascript mods to hide the the links from appearing, but they dont work with the latest versions of Firefox and IE.
And secondly some kind of a check that means after 1 adoptable has been adopted, the member is either taken directly to their profile page or if they do decide to refresh the page, the refresh sends them back to the main adoption page.