|
BugTraq
XSS phpBB 2.0.21 in administration Jul 11 2006 07:55AM renatrix gmail com (1 replies) Re: XSS phpBB 2.0.21 in administration Jul 15 2006 08:48PM Jessica Hope (jessicasaulhope googlemail com) (1 replies) RE: XSS phpBB 2.0.21 in administration Jul 19 2006 05:09AM David Thomson (dave enfinityhost com) (1 replies) |
|
Privacy Statement |
XSS items in the report given, you have to be admin (since they are
all in the admin panel). If you are in the admin panel of any forum,
then there's other things you can do than try fiddle about with XSS.
Jessica
On 7/19/06, David Thomson <dave (at) enfinityhost (dot) com [email concealed]> wrote:
> Defenition from Google, on XSS.
>
> Cross site scripting (XSS) is a type of computer security exploit where
> information from one context, where it is not trusted, can be inserted into
> another context, where it is. From the trusted context, an attack can be
> launched. Note that although cross site scripting is also sometimes
> abbreviated "CSS", it has nothing to do with the Cascading Style Sheets
> technology that is more commonly called CSS.
>
> Example:
>
> A XSS attack is something that an attacker performs, not an admin. You can
> use XSS to retrieve session information, cookies, md5 hashs, password hashes
> all from within a web browser, no need to be an admin.
>
> Hope this helps.
>
[ reply ]