[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Re: New Include Redirect Bug XSS All vBulletin v 3.x.x
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Re: Re: New Include Redirect Bug XSS All vBulletin v 3.x.x
- From: scott-REMOTE-@xxxxxxxxxxxxx
- Date: 22 Jun 2007 11:32:23 -0000
This isn't a directory traversal, the code is simply output on to the page as
<frame src="..."> (sanitised of course), so they can only access what is
available in the physical domain.
Scott MacVicar
Development Team, vBulletin