Full Disclosure mailing list archives
Re: Multiple Phorum XSS and Session Hijacking vulnerabilities
From: Brian Moon <brian () phorum org>
Date: Fri, 02 Sep 2005 11:19:12 -0500
First, all issues that will allow any of the issues here to happen have been fixed. With 5.0.18a, you can not use any method described below. We had the fixes done in less than 24 hours.
Now, what a professional and responsible post. I normally don't reply to these emails, but this person has misrepresented the communications we had with him. It makes me not want to communicate with people that report security flaws. If I had known he would use my words out of context this way, I would have just released the new version and ignored his email.
"Scott" clearly has another agenda here. That is to discredit applications and promote interests of his own. The mention of IPB specifically makes that clear.
Brian Moon Phorum Dev Team _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Multiple Phorum XSS and Session Hijacking vulnerabilities Scott Dewey (Sep 01)
- <Possible follow-ups>
- Re: Multiple Phorum XSS and Session Hijacking vulnerabilities Brian Moon (Sep 02)
- Re: Multiple Phorum XSS and Session Hijacking vulnerabilities Scott Dewey (Sep 02)