Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsForumForumXSS Injection forum 4.5.3XSS Injection forum 4.5.3
Previous
 
Next
New Post
7/5/2010 7:33 AM
 
I have a forum module 4.5.3 running on my website and someone mailed me with the message that it wasn't safe:

He made a post with a javascript to redirect the page to google. So instead of showing the post, the page jumped to google.

I've found an post about this security issue for version 3.2. Has this problem never been solved or is it just me with this problem? I haven't altered the module.

 
New Post
7/5/2010 10:01 AM
 
what version of DotNetNuke are you running? The forums module utilizes some core filtering functions which had issues that were resolved in recent versions.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/5/2010 10:21 AM
 
05.02.03

If an upgrade is needed I've another question.

One is, can I do it myself? I've very little experience with upgrading Dotnetnuke. Last time I tried to update it from version 3.? to 5.2.3 and I failed miserably. Ended up paying a company lots of money to update it for me.
 
New Post
7/6/2010 3:37 AM
 
which version of forums module are you using?

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
8/5/2010 6:25 AM
 
The current website is 5.02.03
The forummodule we're using is 4.5.3

In this situation the forum isn't secure.
 
Is this problem fixed when upgrading the website to 5.04.04?
Or should we upgrade the forum module (if there is a newer version, where can I find it?)
 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsForumForumXSS Injection forum 4.5.3XSS Injection forum 4.5.3


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out