webhostingtalk.nl
advertentie
advertentie

Evenementen voor de komende 60 Dag(en)

Resultaten 1 tot 3 van de 3
          

  1.  
    #1
    virusishacker@gmail.com
    Gast
    n/a Berichten
    Berichten zijn liked




    ipb Css bug(now public)

    the css found when you uploading a file to the server by the "atteched file" function..
    in ipb you can upload some HTML file,in the html file write this:
    <html>
    <body>
    <script>alert('Css found By V[i]RuS');</script>
    </body>
    </html>
    when someone will click on the attechment file the script will run.
    sry about my poor english..
    bug discoverd V[i]RuS
    tested succesfully on ipb 1.0.3 all the vers should be vuln =]


  2. advertentie



  3.  
    #2
    mattmecham@gmail.com
    Gast
    n/a Berichten
    Berichten zijn liked




    Re: ipb Css bug(now public)

    While IPB < 1.3 *might* have been vulnerable, IPB 2.x definitely isn't as HTML files are saved with the mime-type "unknown/unknown" which prompts the user to download the file to their desktop making it totally safe.


  4.  
    #3
    Nicolas Gregoire
    Gast
    n/a Berichten
    Berichten zijn liked




    Re: ipb Css bug(now public)

    Le lundi 08 août 2005 à 13:12 +0000, mattmecham@gmail.com a écrit :

    > While IPB < 1.3 *might* have been vulnerable, IPB 2.x definitely isn't
    > as HTML files are saved with the mime-type "unknown/unknown" which
    > prompts the user to download the file to their desktop making it
    > totally safe.


    <not tested>
    That may be not true for users using (at least) Internet Explorer, as
    "MIME-type sniffing" will be used to determine the file type (and
    handler) to use when opening the file.
    </not tested>

    That's what happen in some Oracle web pages sent with "text/plain" and
    vulnerable to a text/code/JS injection. Oracle isn't to blame (really ?)
    but the browser (if IE) will execute the JavaScript code.


    Regards,
    --
    Nicolas Gregoire ----- Consultant en Sécurité des Systèmes d'Information
    ngregoire@exaprobe.com ------[ ExaProbe ]------ http://www.exaprobe.com/
    PGP KeyID:CA61B44F FingerPrint:1CC647FF1A55664BA2D2AFDACA6A21DACA61B4 4F



Forum Rechten

  • Je mag geen nieuwe onderwerpen plaatsen
  • Je mag geen reacties plaatsen
  • Je mag geen bijlagen toevoegen
  • Je mag jouw berichten niet wijzigen
  •  



webhostingtalk.nl
Webhostingtalk.nl © copyright 2001-2013 Alle Rechten Gereserveerd.

Content Relevant URLs by vBSEO 3.6.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75