|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
A Phorum's bug...
From: WiciU (vviciu
poczta.onet.pl)
Date: Fri May 09 2003 - 12:37:09 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi!
I have founded a bug in Phorum (http://phorum.org/).
It is possible to inject script code or other html-tag into "subject",
"author's name" or "author's e-mail" of a message in Phorum.
In the subject (name, e-mail) input of message you need to write any
html-tag like this:
<<b>script>alert(document.cookie);<<b>/script>
I have tested it on Phorum 3.4.1 but probably works in other Phorum 3.x.x
versions.
Greetings!
WiciU, Poland
vviciu
poczta.onet.pl
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]