Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability

看板Bugtraq作者時間18年前 (2008/01/04 07:05), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/4 (看更多)
This is why browsers block cross-domain AJAX by default. Added to the fact that any action in the ACP requires the SID means that your attack via AJAX would fail. NeoThermic phpBB Support Team, Audit Team and Incident Investigation Team Leader
文章代碼(AID): #17VMf700 (Bugtraq)
文章代碼(AID): #17VMf700 (Bugtraq)