News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Secubos.com:
Cross-Site Scripting Vulnerability in phpFaber
October 31, 2006 @ 11:17:00

A cross-site scripting bug has been announced on the Secuobs.com website for the phpFaber content management system.

Vigilon has reported a vulnerability in phpFaber CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed via the URL in cms_images/js/htmlarea/htmlarea.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

For complete information on the issue, check out this report.

0 comments voice your opinion now!
security issue crosssite scripting xss phpfaber security issue crosssite scripting xss phpfaber


blog comments powered by Disqus

Similar Posts

SitePoint PHP Blog: PHP Security - Dumb Users or Dumb APIs?

PHP Security Consortium: Five SecurityFocus Summaries Posted

Zend Developer Zone: The ZendCon Sessions Episode 1:The State of PHP Security

php[architect]: March 2015 Issue Released - DB Migration

Dan Scott's Blog: Serendipity (s9y) blog: Security release


Community Events

Don't see your event here?
Let us know!


api composer framework podcast php7 example opinion series language yii2 application programming project introduction part2 interview symfony laravel list community

All content copyright, 2015 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework