Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

MyBB 1.2 usercp2.php [ $url ] CrossSiteScripting ( XSS )
From: o.y.6 () hotmail com, ""@securityfocus.com, D3vil-0x1 () securityfocus com
Date: 29 Jan 2006 20:02:42 -0000

Invalid characters removed from From: o.y.6 () hotmail com, |@securityfocus.com,

## MyBB 1.02 usercp2.php XSS
##------------------------------##
## Devil-00 D3vil-0x1 - Attacking MyBB :)##
##                              ##
## devil-00 () s4a cc           ##
##                              ##
##-----------------------------###
##
## File :- usercp2.php
## Var  :- $url
## Line's :-
##              -> 39
##              -> 58
##              -> 84
##              -> 108
##              -> 130
##              -> 149
##              -> 164
##              -> 178
##              -> 192
###################################
## 
## Exploit :-
##-------------------------------------------------------------##
[  Go to any topic .. then go to the end of the page            ]
[  you will see " Add Thread to Favorites "                     ]
[  open the firefox with Live HTTP Headers                      ]
[  and click it .. go to Headers Edit                           ]
[  edit Referer :- "><script>alert(document.cookie);</script>   ]
##-------------------------------------------------------------##
##
## Gr33tz :- www.securitygurus.net
                
                BlackRay <- my new homei
                HACKERS PAL
                Valm0nt
                Abducter
                j7a
                abdalmaged
                Xion
                
                And Others [ S4a Members with SG Members ]
** chow **
                


  By Date           By Thread  

Current thread:
  • MyBB 1.2 usercp2.php [ $url ] CrossSiteScripting ( XSS ) (Jan 30)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]