lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060215103100.14803.qmail@securityfocus.com> Date: 15 Feb 2006 10:31:00 -0000 From: alex@...ln.com To: bugtraq@...urityfocus.com Subject: [eVuln] My Blog BBCode XSS Vulnerabilities New eVuln Advisory: My Blog BBCode XSS Vulnerabilities http://evuln.com/vulns/79/summary.html --------------------Summary---------------- eVuln ID: EV0079 Software: My Blog Sowtware's Web Site: http://fuzzymonkey.net/cgi-bin/download.cgi?file=blog Versions: My Blog 1.63 Critical Level: Harmless Type: Cross-Site Scripting Class: Remote Status: Patched Exploit: Available Solution: Available Discovered by: Aliaksandr Hartsuyeu (eVuln.com) -----------------Description--------------- Arbitrary script code insertion is possible in BBcode [url] and [img] tags. --------------Exploit---------------------- Available at: http://evuln.com/vulns/79/exploit.html --------------Solution--------------------- Install new version: 1.65 Or Replace BBCode.pm module by new one from http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz --------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu (eVuln.com) Regards, Aliaksandr Hartsuyeu http://evuln.com