FireBoard
Welcome, Guest
Please Login or Register.    Lost Password?
phpbb tags phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin (1 viewing) (1) Guests
Go to bottom Post Reply Favoured: 0
TOPIC: phpbb tags phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin
#1456
phpbb tags phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin  
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#1457
Berliner (Visitor)
Click here to see the profile of this user
Birthdate:
phpbb tags phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin  
1. Basically all phpBB admin-side options do allow full HTML, including _java_script__. That is the intended behaviour, as there are legitimate uses. phpBB does however check the Session ID before allowing the changes to go to the data_base_. Your exploit needs a valid admin session key and you need to get the admin to visit the page (unless you happen to have a lot of luck with your IP)- be it by a _link_ or a reflecting page. And even then, it will only work, when the admin has logged into the ACP prior to running into the trap. 2. That is a general problem with all pages allowing of-site pictures. It has been discussed on the list before. Most of your examples won't work with phpBB, due to the missing Session ID in the _link_s. - Hide quoted text -- Show quoted text -
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#1458
phpbb tags phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin  
2. That is a general problem with all pages allowing of-site pictures. It has been discussed on the list before. Most of your examples won't work with phpBB, due to the missing Session ID in the _link_s.
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
Go to top Post Reply
Powered by FireBoardget the latest posts directly to your desktop

Login Form






Lost Password?
No account yet? Register

Syndicate

Who's Online

We have 14 guests online
Conference Organizers Poland - mechanical works - ony Notebook Components - Hotels compare discount - making pictures - French Pocket PC Keyboard - Panasonic - furniture.blogr.com - Fertighäuser - York County - homes for sale - Fertighaus - Website designer Dublin - rachunek wzór - Links patrocinados no Google - Gateway 120W AC Adapter
konto dla firmy
konto dla firmy
emy.systempartnersk…
eXtreme-Fusion CMS
eXtreme-Fusion CMS, eXtreme-Fusion…
extreme-fusion.pl
materace
MATERACE Online
www.materace-online…
nadruki reklamowe
U nas wspania³e nadruki reklamowe
www.nadruki-reklamo…
przeszczep w³osów
Herker - Twoje w³osy
www.herker.pl
901 Pozycjonowanie noclegi zakopane pieluchomajtki kursy i szkolenia Kominki dachowe evening news walking pneumonia samochody rfn adventure tours target coupons