1
kankrelune
newbb 2 HTML/JS problem with message preview ?
  • 2005/3/8 17:58

  • kankrelune

  • Just popping in

  • Posts: 2

  • Since: 2005/1/28


hello...

first, all my excuse for my English more than bad, it is besides for that I never post on the forums of xoops.org... .. .

I will try to make short... .. .

We have look on frxoops.org a "problem of security" in newbb... the html/javascript code is execute when one preview the message before posting... .. .

I do not know myself there enough in the field to be really sure for it but that is rather awkward to see dangerous... .. .

what think you... .. .

@ tchaOo°

2
Mithrandir
Re: newbb 2 security flaw

First off, please don't post security flaws publicly. Contact the developers, giving them a chance to fix it

However, this is something that should be fixed, but the consequences are limited as you have written the message yourself and any malicious code, you would already know about... forward it to the devs, though.

3
wtravel
Re: newbb 2 security flaw

Hi,

From your message I conclude that only the author of a post can execute the javascript code then when previewing the article. If that would be the case then there should not be a problem because he cannot hack the server with it (ordinarily), nor can another user have any damage from it.

I am not a javascript expert but since it is a client tool, theoretically it only influences the PC that opens the preview message.

However, since javascript would not be allowed in the posted messages, perhaps it would be best to also not allow it in preview posts.

Best wishes,

Martijn

4
kankrelune
Re: newbb 2 security flaw
  • 2005/3/8 18:31

  • kankrelune

  • Just popping in

  • Posts: 2

  • Since: 2005/1/28


to Mithrandir

Sorry... the problem did not appear so serious which that I did not pose myself the question... it is clear that for a large fault I would have contacted one of the author directly... but there it is more than one question that of an assertion... .. .

to wtravel

it is what I also think but I like to ask nevertheless... .. .

@ tchaOo°

Login

Who's Online

295 user(s) are online (57 user(s) are browsing Support Forums)


Members: 0


Guests: 295


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Oct 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits