Bug#344674: CVE-2005-4357: phpbb2: XSS with onmouseover

2005-12-28 Thread Jeroen van Wolffelaar
On Tue, Dec 27, 2005 at 11:19:36PM +0100, Thijs Kinkhorst wrote: > Hello Moritz, > > On Sat, December 24, 2005 16:02, Moritz Muehlenhoff wrote: > > The mentioned path disclosure is obviously not a problem, but does > > the described XSS issue have real-world security implications? > > Sorry for n

Bug#344674: CVE-2005-4357: phpbb2: XSS with onmouseover

2005-12-27 Thread Thijs Kinkhorst
Hello Moritz, On Sat, December 24, 2005 16:02, Moritz Muehlenhoff wrote: > The mentioned path disclosure is obviously not a problem, but does > the described XSS issue have real-world security implications? Sorry for not getting back to you earlier, this is due to the holidays. Hope you had a nic

Bug#344674: CVE-2005-4357: phpbb2: XSS with onmouseover

2005-12-24 Thread Moritz Muehlenhoff
Package: phpbb2 Severity: important Tags: security Please have a look at: http://marc.theaimsgroup.com/?l=full-disclosure&m=113484567432679&w=2 The mentioned path disclosure is obviously not a problem, but does the described XSS issue have real-world security implications? Cheers, Moritz