[Full-disclosure] Multiple Phorum XSS and Session Hijacking vulnerabilities

Brian Moon brian at phorum.org
Fri Sep 2 17:19:12 BST 2005


First, all issues that will allow any of the issues here to happen have 
been fixed.  With 5.0.18a, you can not use any method described below. 
We had the fixes done in less than 24 hours.

Now, what a professional and responsible post.  I normally don't reply 
to these emails, but this person has misrepresented the communications 
we had with him.  It makes me not want to communicate with people that 
report security flaws.  If I had known he would use my words out of 
context this way, I would have just released the new version and ignored 
his email.

"Scott" clearly has another agenda here.  That is to discredit 
applications and promote interests of his own.  The mention of IPB 
specifically makes that clear.

Brian Moon
Phorum Dev Team



Full-Disclosure is hosted and sponsored by Secunia.