Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > rocksolid.shared.security > #79

xss in fudforum

Path csiph.com!weretis.net!feeder6.news.weretis.net!i2pn.org!rocksolid2!.POSTED.novabbs-internal!not-for-mail
From Anonymous <poster@anon.com>
Newsgroups rocksolid.shared.security
Subject xss in fudforum
Date Fri, 19 Feb 2021 08:04:12 -0800
Organization rocksolid2 (novabbs.org)
Message-ID <opsec.782.13sp88@anon.com> (permalink)
Content-Type text/plain; charset=UTF-8
Injection-Info novabbs.org; posting-account="def2"; posting-host="novabbs-internal:10.136.143.187"; logging-data="10522"; mail-complaints-to="usenet@novabbs.org"
Xref csiph.com rocksolid.shared.security:79

Show key headers only | View raw


just found this one here:
https://www.exploit-db.com/exploits/47650
and turned off def3 at once. 
not sure when I will turn it back on, seems like there are multiple vulns like this.
at least part of those were fixed with 3.1.0, def3 ran 3.0.7. so now i have to basically either rebuild everything from scratch, or i try to just insert the updated php files in my existing installation. 

hmm....so, def3 will be back, but I guess it will take me a while.

cheers

trw

-- 
Posted on def2

Back to rocksolid.shared.security | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

xss in fudforum Anonymous <poster@anon.com> - 2021-02-19 08:04 -0800
  Re: xss in fudforum Anonymous <poster@anon.com> - 2021-03-03 12:03 -0800
  Re: xss in fudforum Anonymous <poster@anon.com> - 2021-03-03 13:59 -0800
    Re: xss in fudforum retro.guy@rocksolidbbs.com (Retro Guy) - 2021-03-06 07:58 +0000

csiph-web