Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-14457

Malicious user can force "infinite" wait time for everyone else in viewtopic.php

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Blocker Blocker
    • None
    • 3.2.0-b1
    • Posting, Template Engine
    • None

      If a malicious user wants to force a page to take seemingly infinite time to load (making the bulletin board for that content unusable) he can now force it by typing:

      __SCRIPTS_PLACEHOLDER__ 

      Multiple times in his post

            Unassigned Unassigned
            brunoais brunoais
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: