Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13865
HistoryAug 11, 2006 - 12:00 a.m.

Yabb XSS

2006-08-1100:00:00
vulners.com
24

########################################################################
###################

#Aria-Security.net Advisory #

#Discovered by: OUTLAW #

#< www.Aria-security.net > #

#Gr33t to: A.u.r.a & C0d3r & l2odon & R@1D3N @ DrtRp & #

########################################################################
###################

#Software: YaBB

#Attack method: Cross Site Scripting

#Proof of Concept:

#index.php?action=faqmy&myfaq=yes&id_cat=1&categories=<script>alert("xss
")</script>

#----------------------------------------------------------

#Solution

#No Solutions

#Contact : Outlaw (at) aria-security (dot) net [email concealed]