<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[ChipMusic.org - Security issue in profile pages]]></title>
		<link>https://chipmusic.org/forums/topic/17174/security-issue-in-profile-pages/</link>
		<description><![CDATA[The most recent posts in Security issue in profile pages.]]></description>
		<lastBuildDate>Thu, 08 Oct 2015 19:32:10 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235265/#p235265</link>
			<description><![CDATA[<b><i>SketchMan3 says:</i></b><p>I keep getting to these after youve fixed it. I wanted to see what would happen <img src="https://chipmusic.org/forums/img/smilies/sad.png" width="15" height="15" alt="sad" /></p>]]></description>
			<pubDate>Thu, 08 Oct 2015 19:32:10 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235265/#p235265</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235224/#p235224</link>
			<description><![CDATA[<b><i>Delek says:</i></b><p>I also can write code in the title of uploaded songs:<br /><a href="http://chipmusic.org/delek/music/delek---just-one-day" target="_blank">http://chipmusic.org/delek/music/delek---just-one-day</a><br />(note that there&#039;s no website header)</p>]]></description>
			<pubDate>Wed, 07 Oct 2015 14:29:08 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235224/#p235224</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235149/#p235149</link>
			<description><![CDATA[<b><i>Delek says:</i></b><p>Great! It was the lack of htmlentities()/htmlspecialchars() to pre-process the data?</p>]]></description>
			<pubDate>Mon, 05 Oct 2015 18:50:46 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235149/#p235149</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235148/#p235148</link>
			<description><![CDATA[<b><i>nitro2k01 says:</i></b><p>Fixed. If you or anyone else finds vulnerabilities on the site in the future, please contact me or Tim (trash80) directly or send an e-mail to staff at chipmusic dot org.</p>]]></description>
			<pubDate>Mon, 05 Oct 2015 18:02:35 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235148/#p235148</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235147/#p235147</link>
			<description><![CDATA[<b><i>egr says:</i></b><p>Yikes!</p>]]></description>
			<pubDate>Mon, 05 Oct 2015 15:48:38 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235147/#p235147</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235144/#p235144</link>
			<description><![CDATA[<b><i>Dire Hit says:</i></b><div class="quotebox"><cite>DeerPresident wrote:</cite><blockquote><p>Wow. This is actually the most important issue brought up on these forums in a long time.</p></blockquote></div><p>Second most, after the dangers of crowdfunding. Still pretty spooky.</p>]]></description>
			<pubDate>Mon, 05 Oct 2015 14:55:27 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235144/#p235144</guid>
		</item>
		<item>
			<title><![CDATA[Re: Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235143/#p235143</link>
			<description><![CDATA[<b><i>DeerPresident says:</i></b><p>Wow. This is actually the most important issue brought up on these forums in a long time. I guess I just trust people on this site more than I should. <br />I second Delek&#039;s request to have this potential security threat rectified.</p>]]></description>
			<pubDate>Mon, 05 Oct 2015 14:42:19 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235143/#p235143</guid>
		</item>
		<item>
			<title><![CDATA[Security issue in profile pages]]></title>
			<link>https://chipmusic.org/forums/post/235142/#p235142</link>
			<description><![CDATA[<b><i>Delek says:</i></b><p>First please take a second to enter to my profile page: <a href="http://chipmusic.org/delek" target="_blank">http://chipmusic.org/delek</a></p><p>...</p><p>Ok, you&#039;re back now... As you have noticed, you have been redirected to my website instead of seeing my user information. Why does this happen?, because you can actually write code in the links if you know how.</p><p>This should be fixed ASAP, I added just an innocent redirection as an example but very malicious client side code can be injected too.</p>]]></description>
			<pubDate>Mon, 05 Oct 2015 14:26:31 +0000</pubDate>
			<guid>https://chipmusic.org/forums/post/235142/#p235142</guid>
		</item>
	</channel>
</rss>
