Re: SECURITY.NNOV: ikonboard 3.1.1 CSS

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, 4 Oct 2002, 3APA3A wrote:

>   The only change in Ikonboard 3.1.1 (at least on sending private
>   messages)  is  it  checks  URL  extension  to  be  .gif  or  .jpg,  so
>   [IMG]javascript:alert(document.cookie).gif[/IMG]      still      works
>   perfectly....

Not working for me, IconBoard 3.1.1

Error message is
Sorry, dynamic pages in the [IMG] tags are not allowed

raj


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux