Re: Web Wiz Forums ver. 7.01

bruce_at_webwizguide.info
Date: 11/14/03

  • Next message: Jordan Wiens: "Re: [Full-Disclosure] Re: Serious flaws in bluetooth security lead to disclosure of personal data"
    Date: 14 Nov 2003 08:21:18 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <6520144396.20031113223723@hex.net.ru>

    HEX has submitted incorrect information on Web Wiz Forums (again!!!).

    The values of the variables mentioned by HEX are filtered further on in the code.

    The file register_new_user.asp is not a file that exsits in Web Wiz Forums version 7.01 or above.

    The only variable that was not filtered correctly was the Location field which is populated by a drop down box.

    Form March 2003 the location variable was changed to filter the location field.

    This does not effect versions of Web Wiz Forums from 7.5 and above.

    >
    >Informations :
    >°°°°°°°°°°°°
    >Language : ASP
    >Bugged Version : Web Wiz Forums ver. 7.01 (and less ?)
    >Website : http://www.webwizforums.com
    >Problems : Permanent XSS
    >
    >
    >Objects :
    >°°°°°°°
    >- register_new_user.asp
    >- register.asp
    >
    >The values variable are not filtered:
    >
    >strLocation = Request.Form("location")
    >strMessage = Request.Form("signature")
    >strPassword = Request.Form("password")


  • Next message: Jordan Wiens: "Re: [Full-Disclosure] Re: Serious flaws in bluetooth security lead to disclosure of personal data"

    Relevant Pages

    • Re: Filter code not working
      ... Btw, I typically first set the Filter property, then set FilterOn. ... The code works for all fields except the location field. ...
      (microsoft.public.access.formscoding)
    • Filter code not working
      ... I am using this code to filter my form: ... Dim strr As String ... The code works for all fields except the location field. ...
      (microsoft.public.access.formscoding)
    • Re: What kind of filter?
      ... Because hex tanks use shorter side panes, many HOBs will not hang off the ... I find external canisters work best with hex tanks, ... the cabinet door opens wide enough for the filter to fit through;~). ...
      (rec.aquaria.freshwater.misc)
    • What kind of filter?
      ... Going to get the filter for my new tank on thrusday. ... It is a 36g Hex and I plan on having a mix of 4 ...
      (rec.aquaria.freshwater.misc)

  • Quantcast