This page looks plain and unstyled because you're using a non-standard compliant browser. To see it in its best form, please upgrade to a browser that supports web standard_personals. It's free and painless.

Build A Website Blog

Forum Software Contains PHP Security Hole

Skip | 28 October, 2005 18:36

Here's some serious news right before the weekend for you PHP develpers who use the Chipmonk Forum software:

The PHP based Chipmunk Forum contains a flaw that allows a remote cross site scripting attack.

Yeeeeouch....

This flaw exists because the application does not validate the 'forumID' variable upon submission to the 'reply.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.  Be careful when using the PHP developed Chipmonk Forum!

Comments for post

 
Build A Website | Javascript | HTML Help | Persuasive Copywriting | HTML Form | Simple eMail Form | Build A Website Map