Bug#352635: CVE-2006-0437: admin_smilies.php smile_url Variable XSS

2006-02-13 Thread Thijs Kinkhorst
On Mon, 2006-02-13 at 16:50 +1100, Geoff Crompton wrote: Package: phpbb2 Version: 2.0.13-6sarge2 Severity: normal Seen at http://www.osvdb.org/22928. Their description is: phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application

Bug#352635: CVE-2006-0437: admin_smilies.php smile_url Variable XSS

2006-02-12 Thread Geoff Crompton
Package: phpbb2 Version: 2.0.13-6sarge2 Severity: normal Seen at http://www.osvdb.org/22928. Their description is: phpBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'smile_url' variable upon submission to the