Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Re: Re: Re: SMF "index.php?action=pm" Cross Site-Scripting Jan 26 2007 04:53AM
sirdarckcat gmail com
Any way, this vulnerability is not dangerous.. because for sending a successful PM request, you need to match the "sid" variable, that is impossible to get unless you already have control of the session.

The correct patch must be added in the theme file "PersonalMessage.template.php" at the beginin...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus