Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: SMF "index.php?action=pm" Cross Site-Scripting Feb 02 2007 12:16PM
grudge simplemachines org
We intend to release a patch for this and a few other reported bugs within the next day or two (We need to complete testing on it).

Note that this is an extremely difficult exploit to achieve. It requires a user to follow a link posted by someone else to "Send a PM" with some HTML entities within t...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus