News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Secubos.com:
Cross-Site Scripting Vulnerability in phpFaber
October 31, 2006 @ 11:17:00

A cross-site scripting bug has been announced on the Secuobs.com website for the phpFaber content management system.

Vigilon has reported a vulnerability in phpFaber CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed via the URL in cms_images/js/htmlarea/htmlarea.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

For complete information on the issue, check out this report.

0 comments voice your opinion now!
security issue crosssite scripting xss phpfaber security issue crosssite scripting xss phpfaber



Similar Posts

PHPHacks.com: Security in PHP

Secunia.com: Red Hat Update for PHP

PHPClasses.org: PHP security exploit with GIF images

DevShed: Structuring Your Projects for Web Application Security

Dan Scott's Blog: The state of PHP security (LWN article)


Community Events







Don't see your event here?
Let us know!


example releases ajax framework application cakephp PEAR package zendframework job book zend code mysql PHP5 conference release developer database security

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework