Bugtraq mailing list archives
Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability
From: neothermic () phpbb com
Date: 3 Jan 2008 22:28:53 -0000
This is why browsers block cross-domain AJAX by default. Added to the fact that any action in the ACP requires the SID means that your attack via AJAX would fail. NeoThermic phpBB Support Team, Audit Team and Incident Investigation Team Leader
Current thread:
- phpBB2 2.0.22 Cross Site Scripting Vulnerability bugtraq (Jan 02)
- <Possible follow-ups>
- Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability neothermic (Jan 03)
- Re: Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability admin (Jan 03)
- Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability neothermic (Jan 03)
- AW: phpBB2 2.0.22 Cross Site Scripting Vulnerability Aufmuth Andreas (Jan 04)