Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  SPAW Editor PHP Edition

  Mani Admin Plugin Stats Reader V1.2 rfi :)

  WB News Remote File Include in all versions

  aWebNews v 1.1=>RFI

From:meto5757_(at)_hotmail.com <meto5757_(at)_hotmail.com>
Date:02.03.2007
Subject:vBulletin v3.6.5 admincp/index.php ( rss feed ) xss vuln.

vBulletin® v3.6.5 has an xss vuln in admincp/index.php in rss feed .

exactlly in add rss url

by adding :  "><script>alert(document.cookie);</script>

a cool messege box appear with cookies ;)


earlier versions affected also .
-----------------------------------------------------------------------------
Discovered by meto5757


-----------------------------------------------------------------------------

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server