[29617] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Phorum 3.4 Cross Site Scripting

daemon@ATHENA.MIT.EDU (Hagen =?iso-8859-1?Q?K=FChnel?= - )
Thu Apr 3 16:40:09 2003

Date: Thu, 3 Apr 2003 08:26:33 +0200
From: Hagen =?iso-8859-1?Q?K=FChnel?= - HagK <hagk@hagk.de>
To: hagk@hagk.de
Message-ID: <20030403062632.GA2374@tuxmobil.home.hagk.de>
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <20030402131944.18760.qmail@www.securityfocus.com>

Am Mit, 02 Apr 2003, schrieb Peter Stöckli:

> Solution:
> Edit the source code to strip malicious characters from title or escape 
> malicious characters using addslashes().

Phorum 2.4.2 is availaible. 

and the Phorum Homepage:
###
Phorum 3.4.2 Released - SECURITY NOTICE
 Category: New Release    Written by brianlmoon at 6:06pm on April  2, 2003
### 
http://phorum.org/

hagen
-- 
16/ 65
In dem Augenblick, wo wir anfangen unsere Freiheitsrechte
einzuschränken, besorgen wird das Geschäft der Terroristen.
                                              Günter Grass

home help back first fref pref prev next nref lref last post