[39982] in bugtraq
Re: PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)
daemon@ATHENA.MIT.EDU (stuartc1@securityfocus.com,hotmail)
Thu Jul 28 16:28:54 2005
Date: 26 Jul 2005 09:37:32 -0000
Message-ID: <20050726093732.11287.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: stuartc1@securityfocus.com, hotmail@securityfocus.com (at),
com@securityfocus.com (dot)
To: bugtraq@securityfocus.com
Hi,
This is a bugus bug report, I've tested this on both v0.8 and v0.9 and no problems.
Please remove this bug as it gives a bad name to the project.
It is possible to pass fake variables (as with most systems), but not executable code!! which is not a security issue.
If I'm missing something, please email me with details info. But as far as I can see this is a bugus report.
Stuart