BMForum Multiple Cross Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/bmb/topic.php?forumid=6&filename=38496&page=2[XSS-CODE]
http://www.example.com/bmb/topic.php?forumid=6&filename=38496[XSS-CODE]&page=2
http://www.example.com/topic.php?filename=1923[XSS-CODE]
http://www.example.com/bmb/forums.php?forumid=6[XSS-CODE]
http://www.example.com/bmb/forums.php?forumid=6&listby=posttime[XSS-CODE]&jinhua=&page=
http://www.example.com/bmb/forums.php?forumid=6&listby=posttime&jinhua=[XSS-CODE]&page=
http://www.example.com/bmb/forums.php?forumid=6&listby=posttime&jinhua=&page=[XSS-CODE]
http://www.example.com/post.php?forumid=2\[XSS-CODE]
http://www.example.com/announcesys.php?forumid=0[XSS-CODE]


 

Privacy Statement
Copyright 2010, SecurityFocus