about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Simple Machines Forum Size Tag HTML Injection Vulnerability


Title Simple Machines Forum Size Tag HTML Injection Vulnerability
Published 2004-05-05-12:00AM
Updated 2004-05-05-07:52PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  This vulnerability is credited to Cheng Peng Su <apple_soup@msn.com>.
Vulnerable  Simple Machines SMF 1.0 beta5p
Simple Machines SMF 1.0 beta4p
Simple Machines SMF 1.0 beta4.1
Not Vulnerable  
Code   No exploit is required for this issue, however Cheng Peng Su <apple_soup@msn.com> provided some proof-of-concept code.

An attacker could reportedly post content to the forums containing:

[size=expression(alert(document.cookie))]Content[/size]

With the limit that the forum software filters out quotes, apostrophes and semicolons.

Another method that circumvents the software filtering would be to post content such as:

[size=expression(eval(unescape(document.URL.substring(document.URL.length-34,document.URL.length))))]Content[/size]

then get the victim to follow:

http://www.example.com/index.php?topic=12345.0&alert('cookie: '+document.cookie)

Where the '12345.0' is the topic containing the previously posted content. The victim's browser would execute the last 34 characters (as specified in the previously posted 'length-34' content).
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 00:19:01 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c sixy giral www.japanx www.yaogan EAAL free sex p Xnxx.Com darwin+exp mambo Remo t853t www.sexyme Www.sex 40 www.indian taomf.CN maxcpm.inf News Searc Tampilkan, www.lanzho bunnyteens hump www.cankai Reason: 45 Sucunia.co 0777 indian aun Nikikarimi Luck Sex.fr jyothika s porn vedio how to cre www.tamil PORNPICTUR video musi vgx Ax kos ip board 2 hacked by www.zgneng kar20sex www.xc120. news for C freesex vi qhpzxb.blo Vulnerabil Apache/ Indo sek sad PHP Advanc indean+sex