Re: Re: New Include Redirect Bug XSS All vBulletin v 3.x.x

看板Bugtraq作者時間18年前 (2007/06/23 01:49), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/4 (看更多)
This isn't a directory traversal, the code is simply output on to the page as <frame src="..."> (sanitised of course), so they can only access what is available in the physical domain. Scott MacVicar Development Team, vBulletin
文章代碼(AID): #16V0kS00 (Bugtraq)
文章代碼(AID): #16V0kS00 (Bugtraq)