lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20040915231242.3251.qmail@www.securityfocus.com> Date: 15 Sep 2004 23:12:42 -0000 From: <admin@...tflash.com> To: bugtraq@...urityfocus.com Subject: www.proboards.com / YaBB XSS Vuln A Cross Site scripting vulnerability exists currently for all boards of the ever popular www.proboards.com which has code based off of the popular YaBB Forums. This can result in an attacker stealing users Cookie Information and possible defacing/hijacking of the message board and its users accounts on the message board. The following code can be used to execute this XSS vuln: http://WEBSITE/index.cgi?board=[BOARDNAME]&action=display&num=[VALID TOPIC NUMBER]&"><script>alert(document.cookie);</script> Be Cautious of suspicous looking links. ################################## # -LJ Lemke leetflash@...oo.com # ##################################