Cross Site Scripting vulnerability

Phoca Gallery - image gallery extension
Locked
oidia
Phoca Member
Phoca Member
Posts: 10
Joined: 31 Mar 2008, 19:44
Location: Germany

Cross Site Scripting vulnerability

Post by oidia »

Dears,
first of all many thanks for all the good work on all the different Joomla addons!

I just came across the following XSS reported by the Packet Storm website:

packetstormsecurity. com/files/121606/joomlaphocagallery-xss.txt

Maybe you are already aware of, then just ignore this post ;-)

Cheers
Markus
User avatar
Jan
Phoca Hero
Phoca Hero
Posts: 49149
Joined: 10 Nov 2007, 18:23
Location: Czech Republic
Contact:

Re: Cross Site Scripting vulnerability

Post by Jan »

Hi, this was not confirmed, anyway in Phoca Gallery 3.2.4 (latest version) the plupload flash file was updated to newest version. So, solved anyway.

Jan
If you find Phoca extensions useful, please support the project
Locked