From: Andrew Darby <agda...@gmail.com>
Date: Fri, 15 Jun 2012 15:16:05 -0400
Local: Fri, Jun 15 2012 3:16 pm
Subject: Re: [SubjectsPlus] Important: XSS Vulnerability
When I say "gone through all the sites," I mean all the sites listed
on the Sites Using SubjectsPlus page on the wiki. If you're unsure or concerned, drop me a line at agdarby AT gmail DOT com. On Fri, Jun 15, 2012 at 3:14 PM, Andrew Darby <agda...@gmail.com> wrote:
> Oops, I didn't realize I was responding to the whole list. But since > I am . . . I've gone through all the sites, and the only ones with > this vulnerability appear to be showing up in that pastebin link. > Wouldn't hurt to doublecheck your databases.php page, trying out those > test xss attacks. > On Fri, Jun 15, 2012 at 3:07 PM, Andrew Darby <agda...@gmail.com> wrote:
>> Andrew
>> On Fri, Jun 15, 2012 at 3:03 PM, Catherine C Tuohy <tuo...@emmanuel.edu> wrote:
>>> Hello, all. I came across the following pastbin entry today, which
>>> http://pastebin.com/dER2NYKr
>>> I'm not sure what version of SP these sites are running, but you need
>>> $page_title .= ": " . $_GET["letter"];
>>> I'm not sure exactly what it looks like on your site, but for now, try
>>> If you want to see if this is an issue, cut and paste in your database
>>> "><script>alert(1)</script>
>>> if it makes a box pop up, you have a problem. If you're not sure what
>>> This should not be an issue in 1.0.1, but you might have downloaded
>>> --
>>> --
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||