Bugtraq mailing list archives
Re: Advisory #08 - phpBB 2.0.13 Bad filtered in usercp_register.php
From: "vzmule" <vzmule () forever-hack net>
Date: Thu, 3 Mar 2005 13:40:31 -0500 (EST)
// begin original post Vulnerable: $allowhtml = ( isset($HTTP_POST_VARS['allowhtml']) ) ? ( ($HTTP_POST_VARS['allowhtml']) ? TRUE : 0 ) : $board_config['allow_html']; $allowbbcode = ( isset($HTTP_POST_VARS['allowbbcode']) ) ? ( ($HTTP_POST_VARS['allowbbcode']) ? TRUE : 0 ) : $board_config['allow_bbcode']; $allowsmilies = ( isset($HTTP_POST_VARS['allowsmilies']) ) ? ( ($HTTP_POST_VARS['allowsmilies']) ? TRUE : 0 ) : $board_config['allow_smilies']; Fixed: $allowhtml = ( $board_config['allowhtml']) ) ? TRUE : 0; $allowbbcode = ( $board_config['allowbbcode']) ) ? TRUE : 0; $allowsmilies = ( $board_config['allowsmilies']) ) ? TRUE : 0; // end original post. I believe you mean: Fixed: $allowhtml = ( ($board_config['allowhtml']) ) ? TRUE : 0; $allowbbcode = ( ($board_config['allowbbcode']) ) ? TRUE : 0; $allowsmilies = ( ($board_config['allowsmilies']) ) ? TRUE : 0;
Current thread:
- Advisory #08 - phpBB 2.0.13 Bad filtered in usercp_register.php Paisterist (Mar 03)
- Re: Advisory #08 - phpBB 2.0.13 Bad filtered in usercp_register.php vzmule (Mar 03)
- <Possible follow-ups>
- Re: Advisory #08 - phpBB 2.0.13 Bad filtered in usercp_register.php Some one (Mar 05)