RE: CSS in phpBB 1.4.4

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



 > phpBB 1.4.4 is vulnerable to Cross Site Scripting Attack.
> 
> [Vulnerable]
> 
> You can put vbscript in [img] bbcode tags.
> For example:
> 
> [img]vbscript: alert(document.cookie)[/img]

phpBB 1.x hasn't been supported for over two years. All users of phpBB
1.x have been long advised to switch to phpBB 2.x or other system (as
they see fit).

psoTFX - phpbb.com


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux