| SillyDog701 Forums |
| Author |
Message |
J-M


Joined: 25 Jul 2004 Posts: 777 Location: Helsinki, Finland
|
08 Dec, 2006 4:13 pm phpBB 2.0.21 privmsg.php Cross-Site Request Forgery and XSS |
[sdp=80227] |
|
The following security advisory has been released from Secunia:
phpBB privmsg.php Cross-Site Request Forgery and Cross-Site Scripting
From the new advisory:
| Quote: | Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched
 |
What the description says:
| Quote: |
1) The application allows users to send messages via HTTP requests without performing any validity checks to verify the request. | etc.
and
| Quote: |
2) Input passed to the form field "Message body" in privmsg.php is not properly sanitised before it is returned to the user when sending messages to a non-existent user. | etc.
I.e. the second flaw is typical cross-site scripting (XSS) issue.
The report says that the latest version 2.0.21 is affected.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi; rv:1.8.0.8) Gecko/20061025 Firefox/1.5.0.8 Last edited by J-M on 08 Dec, 2006 4:17 pm; edited once(1) |
|
| Back to top |
|
 |
Antony


Joined: 18 Jun 2002 Posts: 12754 Location: Sydney, Australia
|
08 Dec, 2006 4:28 pm |
[sdp=80229] |
|
Thanks J-M,
I will keep an eye on this issue.
UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0
|
|
| Back to top |
|
 |
J-M


Joined: 25 Jul 2004 Posts: 777 Location: Helsinki, Finland
|
11 Dec, 2006 9:10 am |
[sdp=80360] |
|
Thanks for keeping the system secure.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi; rv:1.8.0.8) Gecko/20061025 Firefox/1.5.0.8 |
|
| Back to top |
|
 |
|