[UPHPU] Formbuilder Request for Feedback

phpninja phpninja at gmail.com
Thu Jun 14 12:14:42 MDT 2007


Found an XXS hole in testing a few things, you want to fix this before a
full scale release

http://formbuilder2.esourcehome.com/?module=forms&action=view&ID=%3Cscript%3Ealert(%22sux%20sux%22)%3C/script%3E<script>alert(document.cookie);</script
>

Could be fixed by sanitizing all GET input. Login, click the link and you
will see your cookie.

-phpninja


On 6/14/07, Trevyn Meyer <trevyn at esourcehome.com> wrote:
>
> Great.
> http://esourcehome.com/wiki/index.php?title=Projects
>
> I will be putting up more stuff here shortly.  Let me know if you are
> interested?  And if Alvaro is still on this list, I hope you repond, I
> want your feedback, and I want to learn more about photon.
>
> Trevyn
>
>
> Victor Villa wrote:
> >> mindjuju "i think they have plans to integrate a CRM "
> >> I am curios to know what cause you to ask that?
> >>
> >
> > Trevyn,
> >
> > In an email you sent on 4/11, you said this:
> >
> >
> >> 3 email4CRM
> >> http://esourcehome.com/crm.png
> >> This is a basic CRM tool that I use for form builder or any other
> >> leads that can come in via email.
> >>
> >
> > So when I started to look at your app, I started to research everything
> you
> > said on it previously.
> >
> > mj/v
> >
> >
> >
>
>
> _______________________________________________
>
> UPHPU mailing list
> UPHPU at uphpu.org
> http://uphpu.org/mailman/listinfo/uphpu
> IRC: #uphpu on irc.freenode.net
>


More information about the UPHPU mailing list