Back to list
Re: vbulletin security Alert
May 11 2006 03:53AM
scott vbulletin com
Testing this on a vBulletin 3.5.x-dev build all that I was able to produce was HTML output, no arbitrary PHP code was executed.
You can test this by simply inserting <?php echo "foo"; ?> into a template nothing appears.
If there are more steps please do provide them.
[ reply ]
Copyright 2010, SecurityFocus