lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <6B48648DBA9C3F40B2F97B7CC14AAEB2E77B@dc1.ettanet.local> Date: Wed, 15 Dec 2004 22:15:33 -0000 From: "Paul Owen" <paul@...anet.com> To: <bugtraq@...urityfocus.com> Subject: RE: CSS in phpBB 1.4.4 > phpBB 1.4.4 is vulnerable to Cross Site Scripting Attack. > > [Vulnerable] > > You can put vbscript in [img] bbcode tags. > For example: > > [img]vbscript: alert(document.cookie)[/img] phpBB 1.x hasn't been supported for over two years. All users of phpBB 1.x have been long advised to switch to phpBB 2.x or other system (as they see fit). psoTFX - phpbb.com