»Forumlar »SE ? SQL Injection »Latestposts XSS Açığı (Fixed)
  https://seditio.com.tr/eski1/forums.php?m=posts&q=1955
          Geri Dön      -      Sayfayı Yazdırmak için tıklayın
Author: Ales McGregor, Posted: 2012-06-03 14:04 GMT.
Merhabalar arkada?lar.

Latestposts eklentisinde yeni bulunan XSS a????n? kapatmak i?in basit bir kod deyi?ikli?i edece?iz.

plugins/latestposts/latestposts.php dosyas?n? a?al?m ve a?a?dak? kodu bulal?m.

Kod:
title=\"".$row['ft_title']."


Bu kodla de?i?elim.
Kod:
title=\"".sed_cc($row['ft_title'])."


Latestposts kullanan hər kes bunu uygularsa sorun kalmaz.
Author: M4ster, Posted: 2012-06-04 16:10 GMT.
te?ekk?rler Ales

Powered by SeditioPrint version