If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
Disabled HTML but GB visitor was still able to place HTML..?  XML
Forum Index » Support Forum
Author Message
Anonymous



I went into the ADMIN and disabled HTML codes but just last night I had a visitor to the GB leave a post with HTML right in the posting? How is this possible? It (the posting) was about "Guestbook UmaxSearch Hijackers"...?

URL: http://whsclassof1978.com/classmates/index.php

I am paranoid now since I had my password and username hacked once - what a pain to fix it.
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

You are running an unpatched version of Advanced Guestbook 2.2. Anyone can log in to your admin area. You need to patch ASAP. You will find instructions on how to patch in this forum or at http://www.carbonize.co.uk/Board/viewtopic.php?t=20

DO THIS NOW!

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

I have just tested your guestbook and am pleased to announce that you are successfully patched.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
 
Forum Index » Support Forum
Go to:   
Based on the open source JForum