[問題]又再一個新的phpbb bug

phpBB Installation & Usage Support
phpBB 2 安裝於各類型作業平台之問題討論;外掛問題,請到相關版面依發問格式發表!
(發表文章請按照公告格式發表,違者砍文)

版主: 版主管理群

版面規則
本區是討論關於 phpBB 2.0.X 架設安裝上的問題,只要有安裝任何外掛,請到外掛討論相關版面按照公告格式發表。
(發表文章請按照公告格式發表,違者砍文)
主題已鎖定
eliotsx
星球公民
星球公民
文章: 66
註冊時間: 2003-05-18 14:27

[問題]又再一個新的phpbb bug

文章 eliotsx »

phpBB Privmsg.PHP Cross-Site scripting

phpBB is prone to a cross-site scripting vulnerability in the 'privmsg.php' script. The source of the problem is that HTML and script code are not adequately sanitized from input supplied via URI parameters. This input will be included in dynamically generated web pages. A remote attacker could exploit this issue by embedding hostile HTML and script code in a malicious link to the vulnerable script. The attacker-supplied code will be interpreted in the context of the site hosting the vulnerable software.

The following proof of concept has been supplied:

http://www.example.com/forums/privmsg.p ... e);</scrip
t>post&u=2


大家看一下 不知道這個bug有什麼作用\r
是不是可以取得管理員的cookie ?
主題已鎖定

回到「phpBB 2 安裝與使用」