BugTraq
XSS in Vbulletin 3.6.0 in IE 0nly Aug 03 2006 10:44PM
Stefan dakotacom net
---------------------------------

XSS in Vbulletin 3.6.0 in IE 0nly

---------------------------------

Author: Stefan

Email: stefan (at) dakotacom (dot) net [email concealed]

Group: EnigmaGroup

---------------------------------

Vulnerable: vbulletin 3.5.4 in IE

Vulnerable: vbulletin 3.6.0 in IE

---------------------------------

Javascript may be executed by

saving code as .pdf and uploading

as attachment.This only works in IE

-----------------------------------

Poc: http://www.xandith.com

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus