about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Woltlab Burning Board Multiple Input Validation Vulnerabilites


Title Woltlab Burning Board Multiple Input Validation Vulnerabilites
Published 2009-03-09-12:00AM
Updated 2009-03-12-03:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Juri Gianni aka yeat
Vulnerable  Woltlab Burning Board 3.0.5
Woltlab Burning Board 3.0.3 PL 1
Woltlab Burning Board 3.0
Not Vulnerable  
Code  The attacker can exploit these issues through a browser. To exploit the cross-site scripting and URI-redirection vulnerabilities, the attacker must entice an unsuspecting user to follow a malicious URI.The following example URIs are available:http://www.example.com/[path]/wcf/acp/dereferrer.php?url=javascript:alert("Example");
http://www.example.com/[path]/wcf/acp/dereferrer.php?url=http://[host]
http://www.example.com/[path]/wbb/?page=ThreadAction&action=deleteAll&boardID=1&url=[local URL]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 21 Nov 2009 13:34:53 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
tw.netsh.c omponents/ coppermin news for c phpnukeinp pic sexsy 520mov.kua V& www.WORLDS quicktime cdp Fucking ph %2Fsearch% SEXY GAME www.fwsky. 3.8.1 fake nude www.trish localhost sex carto Www.girlsp Trisha ste www.WORLDS apache exp avec radio waptrickse girls have ass girls Wanawap.Co flash inje php-nuke+2 apache 2.2 www,sex. open cart www.35dir. t275t Www.xnx.co photo of p 2....php?_ all cartoo oscommerce Gmail.com ?mosConfig Powered b play sexy news for c bbs.bubaik SEXY VIDEO photo of p INDYA