Re: Fw: phpBB privmsg.php XSS vulnerability patch.

From: Truthless (nospam_at_spamcop.org)
Date: 02/04/04

  • Next message: Martin Schulze: "[SECURITY] [DSA 433-1] New Linux 2.4.17 packages fix local root exploit (mips+mipsel)"
    Date: Wed, 04 Feb 2004 01:23:43 +0000
    To: Micheal Cottingham <micheal@michealcottingham.com>
    
    

    This is a previously published Vulnerability and not something that is
    yet to be reported.
    Shaun was referring to the patch itself.

    Truthless.

    --
    Micheal Cottingham wrote:
    >
    > If you think you have found a security hole with phpBB, contact the 
    > security email address ... I assure you they won't bite your head off 
    > for notifying them, even if it turns out to be a false alarm.
    >
    > International Veneer Co., Inc. wrote:
    >
    >> ----- Original Message ----- From: "Shaun Colley" <shaunige@yahoo.co.uk>
    >> To: <bugtraq@securityfocus.com>
    >> Sent: Wednesday, January 28, 2004 10:39 AM
    >> Subject: phpBB privmsg.php XSS vulnerability patch.
    >>
    >>
    >> For those who have not yet installed the phpBB
    >> packages fixing the XSS vulnerability in privmsg.php
    >> documented at <http://www.securityfocus.com/bid/9290>
    >> <snip>
    >>
    >>
    >> Thank you for your time.
    >> Shaun.
    >
    >
    >
    

  • Next message: Martin Schulze: "[SECURITY] [DSA 433-1] New Linux 2.4.17 packages fix local root exploit (mips+mipsel)"

    Relevant Pages

    • XSS vulnerability in phpBB (an other ;-)
      ... i've just found a new xss vulnerability in phpBB 2.0.6 (i'm not ... This vulnerability is located in the bbcode. ... there is no patch available but i have warn phpBB developpers so ...
      (Bugtraq)
    • iDEFENSE Security Advisory 02.22.05: phpBB Group phpBB Arbitrary File Disclosure Vulnerability
      ... phpBB Group phpBB Arbitrary File Disclosure Vulnerability ... Remote exploitation of an input validation vulnerability in the phpBB ... allows a remote attacker to control the arguments in a call to copy. ... When a user requests to upload an avatar, ...
      (Bugtraq)
    • [Full-Disclosure] iDEFENSE Security Advisory 02.22.05: phpBB Group phpBB Arbitrary File Disclosure V
      ... phpBB Group phpBB Arbitrary File Disclosure Vulnerability ... Remote exploitation of an input validation vulnerability in the phpBB ... allows a remote attacker to control the arguments in a call to copy. ... When a user requests to upload an avatar, ...
      (Full-Disclosure)
    • Re: Download.ject - commentary - LONG
      ... > patch recently released by Microsoft. ... > vulnerability in question, but instead is just a partial workaround. ... > Granted these are known security best practices related to Internet ... > a new default browser to users and hope that it will be safe enough. ...
      (microsoft.public.win2000.security)
    • Vulnerability Details for MS02-012
      ... Microsoft released a patch for a denial of service ... vulnerability in the Windows 2000 SMTP component. ... This bug affects all Windows 2000 systems running the SMTP service that have ...
      (Bugtraq)

  • Quantcast