Re: Bosdev Multiple vulnerabilities

看板Bugtraq作者時間18年前 (2007/11/14 01:15), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
Actually, you've never emailed us. HTML is stripped from posts, with the exception of admin allowed tags. The username XSS issue is already being dealt with in the 6.1 release. Install.php won't do anything, unless you know the username/password/db name for the system. Admins are told to remove the file specifically for the reason listed above. Next time you say you have emailed someone, you might actually try doing it.
文章代碼(AID): #17ETkR00 (Bugtraq)
文章代碼(AID): #17ETkR00 (Bugtraq)