 |
|
 |
 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 331
Members: 0
Total: 331
|
|
|
|
|
 |
Full disclosure |
 |
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
|
Easyex |
|
Replies: 63 |
Views: 107242 |
|
|
 |
 |
 |
|
It is a threat to other forums/cms
It just depends on how well it's coded and it's authentication.
On PHP-Fusion you can delete members, delete shout box posts, ban users, delete admins and othe ... |
|
|
|
Easyex |
|
Replies: 63 |
Views: 107242 |
|
|
 |
 |
 |
|
Yeah exactly right it would lag...
The best thing for them to do is require confirmination for functions so that it cant be executed, that's what phpbb is doing i believe but it's not that bad sinc ... |
|
|
|
Easyex |
|
Replies: 63 |
Views: 107242 |
|
|
 |
 |
 |
|
nice idea.there are lots of others cms (content manager ) that use bbcode in their post .
you can try popular and widely use cms from
http://hotscripts.com/PHP/Scripts_and_Programs/Content_Man ... |
|
|
|
Easyex |
|
Replies: 63 |
Views: 107242 |
|
|
 |
 |
 |
|
It's not a major issue like PHP-Fusions was
PHP-Fusion was affected badly because you can use index.php and load a header of an admin function and it would automaticly load and execute the function ... |
|
|
|
Easyex |
|
Replies: 63 |
Views: 107242 |
|
|
 |
 |
 |
|
Go talk to NeoThermic from PhpBB and then find out.
No it does not execute on the PhpBB server.
It executes once the page is loaded, It wont show javascript, it wont show the php script it will ... |
|
|
|
Easyex |
|
Replies: 63 |
Views: 107242 |
|
|
 |
 |
 |
|
Obviously you don't know what your talking about.
It wont run a php script will it? Ahh yes that's why i have already showed proof to PhpBB's support team (NeoThermic) and they came up with even mo ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|