Archive for the ‘alerts!’ Category

PHP Forms Security Vulnerability

Thursday, September 20th, 2007
Hello all! I needed to post really quickly for you - this is important! If you have used my contact forms script prior to this moment right now (September 20, 2007 at 9:52am EST), then you need to upgrade. I have removed/disabled downloads to my "complex" and "simple" zipped file outputs. They were old anyway, and needed to go. I do have a replacement "automated" script to generate the simple form for you. (If you need something more complex, feel free to contact me about it, and I'll send it to you.) So, the deal is, an XSS vulnerability was discovered in my script. If you don't know what XSS is (I didn't!), in layman's terms: someone can enter an actual script into any of the input fields on the form, and when they click "submit" said nastiness *will* run. This is a HUGE vulnerability. So this update is no joke. If you're using my forms, you MUST apply the fix, or you're compromising your server, and your host will hate you forever.