This exploit is fixed already.
Hacker can modify message catalog and,
It can possible format string exploit.

Read code at : http://www.xatrix.org/modules.php?op...thread&order=1