06 Jan 2009 @ 1:43 PM 


Thanks to dan20071 for letting me know about this :)

The Problem:

EDITED::…
This was originally reported as link spam, but could easily be a lot worse.

When registering, the user name field is open to possible attack.
Code will be processed on the members page.
The code can be overflown to the homepage fairly easily.
XSS can be used.

I would now consider this as a serious exploit.
I would suggest fixing this bug A.S.A.P

More »

Posted By: Abe
Last Edit: 08 Aug 2009 @ 11:53 AM

EmailPermalinkComments (3)
Tags
Tags: ,
Categories: AV Arcade
Change Theme...
  • Users » 195
  • Posts/Pages » 37
  • Comments » 28
Change Theme...
  • VoidVoid « Default
  • LifeLife
  • EarthEarth
  • WindWind
  • WaterWater
  • FireFire
  • LightLight

DDO Forum



    No Child Pages.

Login



    No Child Pages.