Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
phpBB (privmsg.php) XSS Exploit Jan 11 2007 12:58AM
info burnhead it
phpBB (privmsg.php) XSS Exploit

By: Demential
Web: http://headburn.altervista.org
E-mail: info (at) burnhead (dot) it [email concealed]
PhpBB website: http://phpbb.com

Exploit tested on phpBB 2.0.21

Secunia.com said:

Input passed to the form field "Message body" in privmsg.php
is not properly sanitised before it is returned...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus