[39982] in bugtraq

home help back first fref pref prev next nref lref last post

Re: PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)

daemon@ATHENA.MIT.EDU (stuartc1@securityfocus.com,hotmail)
Thu Jul 28 16:28:54 2005

Date: 26 Jul 2005 09:37:32 -0000
Message-ID: <20050726093732.11287.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: stuartc1@securityfocus.com, hotmail@securityfocus.com (at),
        com@securityfocus.com (dot)
To: bugtraq@securityfocus.com

Hi,

This is a bugus bug report, I've tested this on both v0.8 and v0.9 and no problems.

Please remove this bug as it gives a bad name to the project.

It is possible to pass fake variables (as with most systems), but not executable code!! which is not a security issue.

If I'm missing something, please email me with details info. But as far as I can see this is a bugus report.

Stuart

home help back first fref pref prev next nref lref last post