[8848] Fixed bidding on auctions below starting bid

This was possible by using cheating tools only; the client denies such
actions without sending CMSG_AUCTION_PLACE_BID.
Thanks to leak for reporting this vulnerability.
This commit is contained in:
arrai 2009-11-20 16:03:54 +01:00
parent 166c4feaca
commit b4ce8020e7
2 changed files with 2 additions and 2 deletions

View file

@ -323,7 +323,7 @@ void WorldSession::HandleAuctionPlaceBid( WorldPacket & recv_data )
}
// cheating
if(price <= auction->bid)
if(price <= auction->bid || price < auction->startbid)
return;
// price too low for next bid if not buyout