Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  File Including In PBLang

  [SA17333] phpESP Unspecified Cross-Site Scripting and SQL Injection

  [SA17353] gCards "limit" SQL Injection Vulnerability

  [Full-disclosure] Multiple vulnerabilities within RockLiffe MailSite Express WebMail

From:peanut_(at)_black-rat.no-ip.com <peanut_(at)_black-rat.no-ip.com>
Date:25.10.2005
Subject:Possible Bug in PHP-Fusion 6.0.204

There is a Bug in The News-System:
Post something like:
<me<meta>ta http-equiv = "refresh" content = "1; URL = http://www.google.com">
and you'll be redirected to google.

Possible Solution: use a recursive function to filter metatags.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru