moztw / forum.moztw.org

MozTW Forum
http://forum.moztw.org/
1 stars 3 forks source link

Security issue in OpenID authentication #2

Closed progval closed 10 years ago

progval commented 11 years ago

Hi,

Arbitrary code can be ran through the eval() calls in https://github.com/moztw/forum/blob/master/includes/openid/common.php (last line) and https://github.com/moztw/forum/blob/master/includes/openid/auth.php

Regards, Valentin

appleboy commented 10 years ago

@ProgVal Thanks. We fixed it.