[ Gojko Vujovic @ 17.12.2001. 18:21 ] @
Na bugtraq-u se već danima objavljuju nove rupe (cross site scripting) pronađene u phpnuke newsportal software-u. Evo primera: /modules.php?name=Downloads&d_op=viewdownloaddetails&lid=02&ttitle=[JAVASCRIPT] /modules.php?name=Downloads&d_op=ratedownload&lid=118&ttitle=[JAVASCRIPT] /modules.php?op=modload&name=Members_List&file=index&letter=[JAVASCRIPT] /submit.php?subject=[JAVASCRIPT]&story=[JAVASCRIPT]&storyext=[JAVASCRIPT]&op=Preview /user.php?op=userinfo&uname=[JAVASCRIPT] /modules.php?op=modload&name=Web_Links&file=index&l_op=ratelink&lid=126&ttitle=[script] [...] I naravno, za tim ide poplava hakovanih sajtova. Lako je biti 'haker' ovih dana, zar ne ![]() |