منتدى دعم PBBoard الرسمي
(نسخة قابلة للطباعة من الموضوع)
https://pbboard.info/forums/t10353
أنقر هنا لمشاهدة الموضوع بهيئته الأصلية

تحديث امني Security Patch for Poll to PBBoard v2.1.4
Soliman 06-08-2012 08:24 مساءً
The persistent input validation vulnerabilities can be exploited by remote attackers with low privileged
user account & required user inter action. For demonstration or reproduce ...
To reproduce the vulnerability, the attacker should add a new thread and the check on the add poll button. After that
the attacker can add his malicious code in the answer field of the poll. Anyone who's viewing that thread will be
exploited by the malicious code. Such attack can result in session hijacking, redirecting or cookie theft. Moreover,
the persistent XSS can be exploited to launch a CSRF attack to the user and to exploit the other CSRF vulnerabilities.



Updated files:
modules/new_topic.module.php
modules/topic.module.php




Download Patch to version 2.1.4
5-8-2012_Security_Patch_PBB.zip
منتدى دعم PBBoard الرسمي

Copyright © 2009-2024 PBBoard® Solutions. All Rights Reserved