Vulnerable Version: 3.5.2 (prior versions also may be affected) Bug: Html_Injection (Second order Cross_Site_Scripting) Exploitation: Remote with browser
Html_Injection : The software does not properly filter HTML tags in the title of events before being passed to user in 'calendar.php'&'reminder.php AS include'. that may allow a remote user to inject HTML/javascript codes to events of calendar. The hostil
e code may be rendered in the web browser of the victim user who will Request Reminder for those Events (persistent). For example an attacker creates new event (Single-All Day Event , Ranged Event OR Recurring Event)with this content:
TITLE:--------->Test<script>alert(document.cookie)</script> BODY:---------->No matter OTHER OPTIONS:->No matter
Demonstration XSS URL: -------------------- http://example.com/vbulletin/calenda...addreminder&e=[eventid]
Credit
Savsak.com [Ejder And The_BeKiR And Liz0Zim And CyberLord]

Likes:

Quote