Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Bugtraq: Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability

Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability

From: <neothermic_at_phpbb.com>
Date: 3 Jan 2008 17:28:47 -0000
('binary' encoding is not supported, stored as-is) This exploit is a non-issue. It assumes that you have access to the admin panel. At some point we have to trust that you are a real admin and not a malicious user.

HTML is allowed in some parts of the ACP due to the fact that BBCode is not parsed in these areas.

I would encourage anyone finding a possible vulnerability in phpBB to report it properly at our security tracker ( http://www.phpbb.com/security/ ), or e-mail it to security at phpbb.com

NeoThermic
phpBB Support Team, Audit Team and Incident Investigation Team Leader
Received on Jan 03 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]