Re: Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting

2006-03-09 Thread no_reply
The mentioned issue, ie passing script via the form, will only affect the USER who is doing it. you probably mean the person who is the target of such an attack, right?! It has no effect on the AZbb, the server or the forum That is what XSS is about,it effects the client.

Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting

2006-03-08 Thread no_reply
The mentioned issue, ie passing script via the form, will only affect the USER who is doing it. JavaScripts are client side scripts. It has no effect on the AZbb, the server or the forum.

[CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting

2006-01-28 Thread roozbeh_afrasiabi
PoC : 1) This flaw exists because the application does not validate the nickname variable upon submission to the post.php script via the POST method. h**p://www.[target]/post.php?nickname=scriptalert('XSS')/script!--