View Single Post
  #5 (permalink)  
Old 09-14-2007, 01:52 PM
wige's Avatar
wige wige is offline
Moderator
WebProWorld Moderator
 

Join Date: Jun 2006
Location: United States
Posts: 1,843
wige RepRank 4wige RepRank 4wige RepRank 4wige RepRank 4
Default Re: An excellent forum phpBB toolkit.

Kgun, without knowing much (anything) about the plugin you are using, I do know the message you posted indicates someone attempted an XSS exploit on your forum, which the software picked up.

I think from the error message that the page you were viewing displays a description field for each user being listed, and that description field allows users to create their own content, including HTML code. A user then crafted the malicious description to attack either your administrative account or visitors' accounts when they viewed the description.
__________________
The best way to learn anything, is to question everything.
Reply With Quote