[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20061221031344.6544.qmail@securityfocus.com>
Date: 21 Dec 2006 03:13:44 -0000
From: securityfocus@...iblesoul.com
To: bugtraq@...urityfocus.com
Subject: Re: MkPortal Urlobox Cross Site Request Forgery
I was wrong about this issue in my previous post.
Unofficial Solution:
FIND in /mkportal/modules/urlobox/index.php:
$message = preg_replace('/\[URL=(.+?)\](.+)\[\/URL\]/',$no_url,$message);
$message = preg_replace('/\[IMG\](.+?)\[\/IMG\]/',$no_img,$message);
REPLACE WITH:
$message = preg_replace('/\[URL=(.+?)\](.+)\[\/URL\]/i',$no_url,$message);
$message = preg_replace('/\[IMG\](.+?)\[\/IMG\]/i',$no_img,$message);
-=DKC=-
Powered by blists - more mailing lists