Re: UBB vulnerablietis + about: using example

From: David Dreezer (bugtraqat_private)
Date: Thu Nov 15 2001 - 14:40:45 PST

  • Next message: uid0at_private: "AT&T/@Home Cable Modem Enumeration"

    
     ('binary' encoding is not supported, stored as-is)
    Mailer: SecurityFocus
    In-Reply-To: <15722392656.20011116021050at_private>
    
    This has been filtered in our product since version 
    5.47e, released February 21, 2001
    
    line 767 ubb_library.cgi
    
    if ($ThePost =~ /\ONERROR\s*=/i) {
    	&StandardHTML("Illegal HTML tag, 
    ONERROR");
    	exit;
    
    line 709 of the latest version.
    
    Perhaps had you followed the accepted procedures 
    and notified us, the vendor, ahead of time we could 
    have pointed this out to you.
    
    Actions such as this reduce the value of bugtraq. 
    



    This archive was generated by hypermail 2b30 : Thu Nov 15 2001 - 17:53:23 PST