Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: www.proboards.com / YaBB XSS Vuln

www.proboards.com / YaBB XSS Vuln

From: <admin_at_leetflash.com>
Date: 15 Sep 2004 23:12:42 -0000
('binary' encoding is not supported, stored as-is) A Cross Site scripting vulnerability exists currently for all boards of the ever popular www.proboards.com which has code based off of the popular YaBB Forums.

This can result in an attacker stealing users Cookie Information and possible defacing/hijacking of the message board and its users accounts on the message board.

The following code can be used to execute this XSS vuln:

http://WEBSITE/index.cgi?board=[BOARDNAME]&action=display&num=[VALID TOPIC NUMBER]&">&lt;script&gt;alert(document.cookie);&lt;/script&gt;

Be Cautious of suspicous looking links.

##################################
# -LJ Lemke leetflash_at_yahoo.com #
##################################
Received on Sep 16 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos