BugTraq
www.proboards.com / YaBB XSS Vuln Sep 15 2004 11:12PM
admin leetflash com (1 replies)


A Cross Site scripting vulnerability exists currently for all boards of the ever popular www.proboards.com which has code based off of the popular YaBB Forums.

This can result in an attacker stealing users Cookie Information and possible defacing/hijacking of the message board and its users accounts on the message board.

The following code can be used to execute this XSS vuln:

http://WEBSITE/index.cgi?board=[BOARDNAME]&action=display&num=[VALID TOPIC NUMBER]&"><script>alert(document.cookie);</script>

Be Cautious of suspicous looking links.

##################################

# -LJ Lemke leetflash (at) yahoo (dot) com [email concealed] #

##################################

[ reply ]
RE: www.proboards.com / YaBB XSS Vuln Sep 16 2004 09:10PM
GulfTech Security (security gulftech org)


 

Privacy Statement
Copyright 2010, SecurityFocus