Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Security Concern???
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Security Concern???

 Post Reply Post Reply
Author
lodogg View Drop Down
Groupie
Groupie


Joined: 22 August 2003
Location: United States
Status: Offline
Points: 161
Post Options Post Options   Thanks (0) Thanks(0)   Quote lodogg Quote  Post ReplyReply Direct Link To This Post Topic: Security Concern???
    Posted: 22 October 2003 at 9:40am

http://marc.theaimsgroup.com/?l=bugtraq&m=10667756912779 2&w=2

 

Is this true?  That would really suck!  And if so will there be a fix??

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 11:42am
Not only is this a very minor X site scripting issue and absolutly nothing to worry about.

It doesn't effect the latest version, Web Wiz Forums version 7.5.

The person who sumitted this bug track also emailed it to me I tried to responed to him, "HEX" <hex@hex.net.ru>, telling him that the bug track report he submitted to security focus is wrong but the email address is incorrect.

I also emailed securityfocus.com where is was submitted telling them this submission was incorrect but they published it anyway. I have emailed them again demending that they correct it or remove it.
  1. It doesn't effect version 7.5 (the latest version), so no need to wait for a patch
  2. I knew and wrote a fix to this last Easter.
  3. Version 7.01 that this bug report is on doesn't have a file called forum_members.asp so it is incorrect.
  4. Saying that there is no patch for this is incorrect in this bug report as a fix has already been written and this doesn't effect the latest version.
If you are running a version older than 7.5 don't worry to much as this is not a majour concern, it just means that someone can add some info to a querystring (in there own browser) that makes the forum do something it shouldn't, like show an JavaScript alert box, but nothing that is harmful or effect other users.


Edited by -boRg-
Back to Top
lodogg View Drop Down
Groupie
Groupie


Joined: 22 August 2003
Location: United States
Status: Offline
Points: 161
Post Options Post Options   Thanks (0) Thanks(0)   Quote lodogg Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 12:36pm

Should I upgrade to 7.5?  Or will it be more of a pain in the as*  I'm running 7.01 with a *.mdb.

 

Thanks

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 12:49pm
If you look in the web wiz forums forum there is a post on how to upgrade which is releativly simple for access versions.
Back to Top
lodogg View Drop Down
Groupie
Groupie


Joined: 22 August 2003
Location: United States
Status: Offline
Points: 161
Post Options Post Options   Thanks (0) Thanks(0)   Quote lodogg Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 1:09pm
Cool thanxs for the help
Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 4:33pm
hey borg! can you upgrade from v7.01 to v7.5 by just using the same database? (Basically is there going to be any errors that develop if i just using the same database that i used with v7.01)
Back to Top
MadDog View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 01 January 2002
Status: Offline
Points: 3008
Post Options Post Options   Thanks (0) Thanks(0)   Quote MadDog Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 5:54pm
Do a search pmormr!
Back to Top
lodogg View Drop Down
Groupie
Groupie


Joined: 22 August 2003
Location: United States
Status: Offline
Points: 161
Post Options Post Options   Thanks (0) Thanks(0)   Quote lodogg Quote  Post ReplyReply Direct Link To This Post Posted: 22 October 2003 at 5:59pm

http://forums.webwiz.net/forum_posts.asp?TID=6136&a mp;PN=1

 

Here ya go pmormr...  I just upgraded my site and there was no problems.  But then again I have ms access not sql!

Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.