<<<
Date Index
>>>
<<<
Thread Index
>>>
Re: XSS vulnerability in phpBB (an other ;-)
To
: John Smith <
sgaesux@xxxxxxxxxxxx
>
Subject
: Re: XSS vulnerability in phpBB (an other ;-)
From
: Michael Renzmann <
security@xxxxxxxxxx
>
Date
: Tue, 09 Sep 2003 18:39:21 +0200
Cc
:
bugtraq@xxxxxxxxxxxxxxxxx
In-reply-to
: <
20030909072405.5AB411A01C8@xxxxxxxxxxxxxxxxx
>
List-help
: <
mailto:bugtraq-help@securityfocus.com
>
List-id
: <bugtraq.list-id.securityfocus.com>
List-post
: <
mailto:bugtraq@securityfocus.com
>
List-subscribe
: <
mailto:bugtraq-subscribe@securityfocus.com
>
List-unsubscribe
: <
mailto:bugtraq-unsubscribe@securityfocus.com
>
Mailing-list
: contact
bugtraq-help@xxxxxxxxxxxxxxxxx
; run by ezmlm
Organization
: Dylanic GmbH
References
: <
20030909072405.5AB411A01C8@xxxxxxxxxxxxxxxxx
>
User-agent
: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3) Gecko/20030312
Hi. John Smith wrote:
[url=
http://www.izhal.com"
; onclick=alert("bug");"]test[/url]
Checked that variant with phpBB 2.0.1 again, and it didn't work as well.
Seems as this version is not vulnerable.
Bye, Mike
References
:
Re: XSS vulnerability in phpBB (an other ;-)
From:
John Smith
Prev by Date:
Re: XSS vulnerability in phpBB (an other ;-)
Next by Date:
Re: 11 years of inetd default insecurity?
Previous by thread:
Re: XSS vulnerability in phpBB (an other ;-)
Next by thread:
Re: XSS vulnerability in phpBB (an other ;-)
Index(es):
Date
Thread