Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Peter Stöckli
    Phorum 3.4 Cross Site Scripting
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Phorum 3.4 Cross Site Scripting



    Description:
    It is possible to insert javascript code in a message and execute it.

    1.) go to a phorum
    2.) click on new topic
    3.) enter any name
    4.) enter any email
    5.) enter a title in the way like this "><script>alert
    ("Vulnerable");</script>
    6.) enter any text
    7.) click the preview button
    8.) click the send button on the top of the page

    Solution:
    Edit the source code to strip malicious characters from title or escape
    malicious characters using addslashes().

  2. #2
    Hagen =?iso-8859-1?Q?K=FChnel?= - HagK
    Phorum 3.4 Cross Site Scripting
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Phorum 3.4 Cross Site Scripting

    Am Mit, 02 Apr 2003, schrieb Peter Stöckli:

    > Solution:
    > Edit the source code to strip malicious characters from title or escape
    > malicious characters using addslashes().


    Phorum 2.4.2 is availaible.

    and the Phorum Homepage:
    ###
    Phorum 3.4.2 Released - SECURITY NOTICE
    Category: New Release Written by brianlmoon at 6:06pm on April 2, 2003
    ###
    http://phorum.org/

    hagen
    --
    16/ 65
    In dem Augenblick, wo wir anfangen unsere Freiheitsrechte
    einzuschränken, besorgen wird das Geschäft der Terroristen.
    Günter Grass

  3. #3
    Brian Moon
    Phorum 3.4 Cross Site Scripting
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Phorum 3.4 Cross Site Scripting

    In-Reply-To: <20030402131944.18760.qmail@www.securityfocus.com>

    FYI, the versions prior to 3.4 did not have this problem.

    Brian.
    Phorum Dev Team

    >From: Peter "Stöckli" <pcs@pcsmedia.net>
    >To: bugtraq@securityfocus.com
    >Subject: Phorum 3.4 Cross Site Scripting
    >
    >
    >
    >Description:
    >It is possible to insert javascript code in a message

    and execute it.
    >
    >1.) go to a phorum
    >2.) click on new topic
    >3.) enter any name
    >4.) enter any email
    >5.) enter a title in the way like this

    ">&lt;script&gt;alert
    >("Vulnerable");&lt;/script&gt;
    >6.) enter any text
    >7.) click the preview button
    >8.) click the send button on the top of the page
    >
    >Solution:
    >Edit the source code to strip malicious characters

    from title or escape
    >malicious characters using addslashes().
    >


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics