Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  phpPollScript  - 1.3 Remote File Include

  [ISecAuditors Security Advisories] PHP-Calendar <= v1.1 'configfile' Remote and Local File Inclusion vulnerability

  [ISecAuditors Security Advisories] Simple PHP Blog <= 0.5.1 Local File Include vulnerability

  Re: Powered By Dvbbs Version 7.1.0 Sp1 By Pass

From:irancrash_(at)_gmail.com <irancrash_(at)_gmail.com>
Date:21.12.2009
Subject:SMF (Simple Machine Forum) 1.1.11 XSS - Discovered by : Khashayar Fereidani


|| Script : SMF (Simple Machine Forum) 1.1.11
|| Vulnerability Type : Active XSS ( Active Cross Site Scripting )
|| Risk : Low

|| Discovered By Khashayar Fereidani
|| http://ircrash.com http://bugtraq.ircrash.com


|| Note :

For use this vulnerability you need access to censor words panel .
1.First login and go to : http://site/path/index.php?action=postsettings;sa=censor
click on "Click here to add another word." for add new row .
set new text box : ircrash => "<script>alert('Vulnerable')</script>
and save page .
2.Open new typic and set title : ircrash , fill all fields and post typic .
3.Open forum home page . you see alert : Vulerable

You can set any html or java script code . hackers can home deface forum or set activex for virus .

|| Solution : filter censor page variables with htmlspecialchars .
|| Tnx : Only For God

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server