[40858] in bugtraq
Possible Bug in PHP-Fusion 6.0.204
daemon@ATHENA.MIT.EDU (peanut@black-rat.no-ip.com)
Mon Oct 24 16:41:33 2005
Date: 24 Oct 2005 16:44:25 -0000
Message-ID: <20051024164425.2853.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: peanut@black-rat.no-ip.com
To: bugtraq@securityfocus.com
There is a Bug in The News-System:
Post something like:
<me<meta>ta http-equiv = "refresh" content = "1; URL = http://www.google.com">
and you'll be redirected to google.
Possible Solution: use a recursive function to filter metatags.