UBB is prone to cross-site scripting attacks via the insertion of HTML tags into image links in messages. Due to insufficient input validation, it is possible to insert arbitrary script code in forum messages/replies. The malicious script code will be executed in the browser of the user viewing the message, in the context of the site running UBB.

[enough with the linking already, we fixed this last week...]

Comments?

[This message was edited by Charles Capps on 18 Jan 02 at 10:23 AM.]

[This message was edited by Charles Capps on November 05, 2002 at 09:37 AM.]