Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

VBulletin Multiple Cross-Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/modcp/index.php?do=frames&loc=[XSS]
http://www.example.com/modcp/user.php?do=gethost&ip=[XSS]
http://www.example.com/admincp/css.php?do=doedit&dostyleid=1&group=[XSS]
http://www.example.com/admincp/index.php?redirect=[XSS]
http://www.example.com/admincp/index.php?do=frames&loc=[XSS]
http://www.example.com/admincp/user.php?do=emailpassword&email=[XSS]
http://www.example.com/admincp/usertitle.php?do=gethost&ip=[XSS]
http://www.example.com/admincp/language.php?do=rebuild&goto=[XSS]
http://www.example.com/admincp/modlog.php?do=view&orderby=[XSS]
http://www.example.com/admincp/template.php?do=colorconverter&hex=[XSS]
http://www.example.com/admincp/template.php?do=colorconverter&rgb=[XSS]
http://www.example.com/admincp/template.php?do=modify&expandset=[XSS]
http://www.example.com/admincp/vbugs_admin.php?do=updateseverity&vbug_severityid=1%20/*[XSS]







 

Privacy Statement
Copyright 2009, SecurityFocus