XSS VULN IN ALL MYBB VERSIONS (INCLUDING PR2) Vendor: given SEVEN days notice, no patch released! Just to say, I am apalled with the fact that I contacted MyBB on the 30 August, and was originally not planning to go public. However, because they have failed to release a patch I have decided to alert the wider community. At the bottom of every page shown to the admins is a debug link. Unfortunately, this fails to properly sanitize user input, so, for example, you could try: 'forumdisplay.php?fid=2&datecut="">] and ouch! robokoder fusionnx.com- The Web Developer's Resource Centre ##################################################################################### This email has been scanned by MailMarshal, an email content filter. #####################################################################################