phpBB 2.0.21 privmsg.php Cross-Site Request Forgery and XSS

For all tech/computer related or even internet related discussions not covered in other sections. Also iPad, iPhone, iPod and multimedia discussions.

Moderators: profman, Josh, Don_HH2K

phpBB 2.0.21 privmsg.php Cross-Site Request Forgery and XSS

Postby J-M » Fri 08 Dec, 2006 5:13 pm

The following security advisory has been released from Secunia:
phpBB privmsg.php Cross-Site Request Forgery and Cross-Site Scripting

From the new advisory:

Critical: Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Unpatched


What the description says:
1) The application allows users to send messages via HTTP requests without performing any validity checks to verify the request.
etc.

and
2) Input passed to the form field "Message body" in privmsg.php is not properly sanitised before it is returned to the user when sending messages to a non-existent user.
etc.

I.e. the second flaw is typical cross-site scripting (XSS) issue.
The report says that the latest version 2.0.21 is affected.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi; rv:1.8.0.8) Gecko/20061025 Firefox/1.5.0.8
Last edited by J-M on Fri 08 Dec, 2006 5:17 pm, edited 1 time in total.
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby Antony » Fri 08 Dec, 2006 5:28 pm

Thanks J-M,

I will keep an eye on this issue.
UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0
User avatar
Antony
diamond member
diamond member
 
Posts: 14343
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby J-M » Mon 11 Dec, 2006 10:10 am

Thanks for keeping the system secure.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi; rv:1.8.0.8) Gecko/20061025 Firefox/1.5.0.8
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland


Return to General Computing and Tech

Who is online

Registered users: Google [Bot]