|
VBulletin Multiple Cross-Site Scripting Vulnerabilities
No exploit is required. The following proof of concept URI are available: http://www.example.com/modcp/index.php?do=frames&loc=[XSS] http://www.example.com/modcp/user.php?do=gethost&ip=[XSS] http://www.example.com/admincp/css.php?do=doedit&dostyleid=1&group=[XSS] http://www.example.com/admincp/index.php?redirect=[XSS] http://www.example.com/admincp/index.php?do=frames&loc=[XSS] http://www.example.com/admincp/user.php?do=emailpassword&email=[XSS] http://www.example.com/admincp/usertitle.php?do=gethost&ip=[XSS] http://www.example.com/admincp/language.php?do=rebuild&goto=[XSS] http://www.example.com/admincp/modlog.php?do=view&orderby=[XSS] http://www.example.com/admincp/template.php?do=colorconverter&hex=[XSS] http://www.example.com/admincp/template.php?do=colorconverter&rgb=[XSS] http://www.example.com/admincp/template.php?do=modify&expandset=[XSS] http://www.example.com/admincp/vbugs_admin.php?do=updateseverity&vbug_severityid=1%20/*[XSS] |
|
|
Privacy Statement |