OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: XSS vulnerability in phpBB (an other ;-)

From: Michael Renzmann (securitydylanic.de)
Date: Tue Sep 09 2003 - 11:39:21 CDT


Hi.

John Smith wrote:
> [url=http://www.izhal.com" onclick=alert("bug");"]test[/url]

Checked that variant with phpBB 2.0.1 again, and it didn't work as well.
Seems as this version is not vulnerable.

Bye, Mike