OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Phorum 3.4 Cross Site Scripting

From: Hagen Kühnel - HagK (hagkhagk.de)
Date: Thu Apr 03 2003 - 00:26:33 CST


Am Mit, 02 Apr 2003, schrieb Peter Stöckli:

> Solution:
> Edit the source code to strip malicious characters from title or escape
> malicious characters using addslashes().

Phorum 2.4.2 is availaible.

and the Phorum Homepage:
###
Phorum 3.4.2 Released - SECURITY NOTICE
 Category: New Release Written by brianlmoon at 6:06pm on April 2, 2003
###
http://phorum.org/

hagen
--
16/ 65
In dem Augenblick, wo wir anfangen unsere Freiheitsrechte
einzuschränken, besorgen wird das Geschäft der Terroristen.
                                              Günter Grass