BugTraq
XSS phpBB 2.0.21 in administration Jul 11 2006 07:55AM
renatrix gmail com (1 replies)
Re: XSS phpBB 2.0.21 in administration Jul 15 2006 08:48PM
Jessica Hope (jessicasaulhope googlemail com) (1 replies)
RE: XSS phpBB 2.0.21 in administration Jul 19 2006 05:09AM
David Thomson (dave enfinityhost com) (1 replies)
Re: XSS phpBB 2.0.21 in administration Jul 19 2006 07:17AM
Jessica Hope (jessicasaulhope googlemail com)
I know what XSS is. I'm pointing out the fact that to do any of the
XSS items in the report given, you have to be admin (since they are
all in the admin panel). If you are in the admin panel of any forum,
then there's other things you can do than try fiddle about with XSS.

Jessica

On 7/19/06, David Thomson <dave (at) enfinityhost (dot) com [email concealed]> wrote:
> Defenition from Google, on XSS.
>
> Cross site scripting (XSS) is a type of computer security exploit where
> information from one context, where it is not trusted, can be inserted into
> another context, where it is. From the trusted context, an attack can be
> launched. Note that although cross site scripting is also sometimes
> abbreviated "CSS", it has nothing to do with the Cascading Style Sheets
> technology that is more commonly called CSS.
>
> Example:
>
> A XSS attack is something that an attacker performs, not an admin. You can
> use XSS to retrieve session information, cookies, md5 hashs, password hashes
> all from within a web browser, no need to be an admin.
>
> Hope this helps.
>

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus