Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Registration Security Question Plugin - XSS Vulnerability
#1
A member told me that there was an XSS vulnerability in this plugin:

http://mods.mybb.com/view/registration-s...y-question

I highly doubt it, considering the author is a support technician, but is this true?
#2
I don't know how there would be an XSS in that plugin. The user input is never displayed. If you can display HTML in the question, that's not an XSS vulnerability.

Ask him for a proof of concept.
-Paul H.

Cogisne lingua latina?
#3
http://gyazo.com/67eee063434853a21984805...1356133601

It appears to be because of that.
#4
Line 37:
	$prefix = 'g33k_'.$codename.'_';

No problem there.
He said something similar here about another plugin: http://yaldaram.com/thread-4963-post-225...l#pid22585

That line is empty.

He's just trying to be a l33t hacker scaring people.
-Paul H.

Cogisne lingua latina?
#5
Ah, thanks.

Just wanted to make sure.
#6
@ Xeronations - next time you think there might be a vulnerability please report it in Private Inquiries rather than the open forum.
Random Fish and Sims Maniac
MY PLUGINS
Help MyBBSupport help you - remember to mark your threads as solved


#7
(2012-12-22, 12:28 AM)Paul H. Wrote: Line 37:
	$prefix = 'g33k_'.$codename.'_';

No problem there.
He said something similar here about another plugin: http://yaldaram.com/thread-4963-post-225...l#pid22585

That line is empty.

He's just trying to be a l33t hacker scaring people.

CAN WE REMOVE THAT LINE????
Line 37:
	$prefix = 'g33k_'.$codename.'_';
#8
(2015-02-09, 08:10 AM)Dr_The_One Wrote: CAN WE REMOVE THAT LINE????
Line 37:
	$prefix = 'g33k_'.$codename.'_';

Uhhhh... no. If you do that, you'll break the plugin's ability to function.
PGP Key (Fingerprint: 23B6 F4C0 FE2D 45AA 61A0 1E86 DB87 09DC DD87 6E40)
#9
Read: http://community.mybb.com/thread-129189-page-2.html
The updated reg security question file download is the last post.
Update your files with it and make a change or two to your questions and then the plug-in will works as designed.


Forum Jump:


Users browsing this thread: 1 Guest(s)