Home page logo
/

bugtraq logo Bugtraq mailing list archives

CSS in phpBB 1.4.4
From: "SandI]" <agent050 () sama ru>
Date: Wed, 15 Dec 2004 23:23:55 +0400

I found a bug in quite old forum system phpBB 1.4.4

phpBB 1.4.4 is vulnerable to Cross Site Scripting Attack.

[Vulnerable]

You can put vbscript in [img] bbcode tags.
For example:

[img]vbscript: alert(document.cookie)[/img]

Author: Gurjanov Ilia or Net
agent050 () sama ru


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]