Home page logo

bugtraq logo Bugtraq mailing list archives

XMB Forum 1.9.5-Final XSS
From: r0xes.ratm () gmail com
Date: 9 Apr 2006 00:11:35 -0000

XMB Forum 1.9.5 (I have not tested this on earlier versions)
allows users to embed flash (.swf) videos in their posts.
Normally, you could set an option on the <object> tag to say that ActionScript cannot run, but in this case we don't.

The way we execute our code is by making a flash movie containing the Actionscript code:

An example video + .fla script can be downloaded at my site: http://dynxss.whiteacid.org/videos/xmbforum_1.9.5-final.rar

XMB has been notified, expect this to be fixed in a few days.

comments, questions, flames, etc.
r0xes [dot] ratm [at] gmail [dot] com

  By Date           By Thread  

Current thread:
  • XMB Forum 1.9.5-Final XSS r0xes . ratm (Apr 10)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]