Re: XSS in JAB Guest Book

2006-12-09 Thread Barnz
Hello, The problem should not be fixed in the download, using the strip_tags() functions.

Re: XSS in JAB Guest Book

2006-12-07 Thread Steven M. Christey
>function invalideregtest($input) > >script just check $topic by invalideregtest function I think this function just *tries* to check inputs, but doesn't succeed. Did you do any live testing using $topic ? We should expect to see more erroneous cleansing/checking functions as programmers attemp

XSS in JAB Guest Book

2006-12-04 Thread nj
Script Name: JAB Guest Book Authors: [EMAIL PROTECTED] Website: James Barnsley Bug Report: NetJackal (nj[AT]hackerz[DOT]ir & nima_501[AT]yahoo[DOT]com) Status: Patch not released First i should apologize for my bad english. Intro: JAB Guest Book is a free guest book written in PHP, it works