Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    the_bekir@savsak.com
    Html_Injection in vBulletin 3.5.2
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Html_Injection in vBulletin 3.5.2

    Vulnerable Version: 3.5.2 (prior versions also may be affected) Bug: Html_Injection (Second order Cross_Site_Scripting) Exploitation: Remote with browser


    Html_Injection : The software does not properly filter HTML tags in the title of events before being passed to user in 'calendar.php'&'reminder.php AS include'. that may allow a remote user to inject HTML/javascript codes to events of calendar. The hostil
    e code may be rendered in the web browser of the victim user who will Request Reminder for those Events (persistent). For example an attacker creates new event (Single-All Day Event , Ranged Event OR Recurring Event)with this content:


    TITLE:--------->Test<script>alert(document.cookie)</script> BODY:---------->No matter OTHER OPTIONS:->No matter


    Demonstration XSS URL: -------------------- http://example.com/vbulletin/calenda...addreminder&e=[eventid]

    Credit

    Savsak.com [Ejder And The_BeKiR And Liz0Zim And CyberLord]

  2. #2
    Steven M. Christey
    Html_Injection in vBulletin 3.5.2
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Html_Injection in vBulletin 3.5.2


    This appears to be the same vulnerability as that reported to Bugtraq
    by trueend5 of KAPDA on January 1:

    BUGTRAQ:20060106 [KAPDA::#19] - Html Injection in vBulletin 3.5.2
    URL:http://www.securityfocus.com/archive...100/0/threaded

    In fact, the text is exactly the same, as is the example.

    - Steve

  3. #3
    info@hoder.com
    Html_Injection in vBulletin 3.5.2
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Html_Injection in vBulletin 3.5.2

    OK .
    First see this :
    http://www.securityfocus.com/archive...0/120/threaded

    Credit ?
    Savsak.com [Ejder And The_BeKiR And Liz0Zim And CyberLord]

    So what is this ?
    Credit :
    --------------------
    Discovered & released by trueend5 (trueend5 kapda ir)
    Security Science Researchers Institute Of Iran
    [http://www.KAPDA.ir]

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics