Search found 3 matches

by drow
Wed Dec 09, 2009 8:39 pm
Forum: General Discussion
Topic: XSS and the search module
Replies: 3
Views: 2438

XSS and the search module

an audit was dinging us for an XSS vulnerability related to the search form on the website.  basically, a request for...     GET /cgi-bin/blah blah blah; results in our 404 page, which includes...     blah blah blah;">           i'm pretty sure that no modern browser is going to parse a inside ...
by drow
Sat Jul 18, 2009 5:46 am
Forum: CMSMS Core
Topic: pages list, icons do nothing [solved]
Replies: 2
Views: 1244

Re: pages list, icons do nothing

PHP 5.2.6, safe mode is disabled. from the server access log, i'm guessing that xajax is the thing i'm looking for? is the server-side code in the same directory tree?  because i only see requests for the client-side javascript. hmm... javascript is definitely executing in the web browser, though. w...
by drow
Fri Jul 17, 2009 10:10 pm
Forum: CMSMS Core
Topic: pages list, icons do nothing [solved]
Replies: 2
Views: 1244

pages list, icons do nothing [solved]

this is a bit curious, and i suspect that its something more or less specific to me, but i figured i'd ask. i've had both CMSMS 1.2.4 and now 1.6 installed.  in either version, in the list of pages (Content -> Pages), many of the various icons associated with each page don't do anything when i click...

Go to advanced search