lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060302020821.30771.qmail@securityfocus.com> Date: 2 Mar 2006 02:08:21 -0000 From: addmimistrator@...il.com To: bugtraq@...urityfocus.com Subject: [KAPDA::#26]vBulletin.3.5.3~3.0.12-XSS original advisories: http://www.kapda.ir/advisory-266.html http://myimei.com/security/2006-02-19/vbulletin3012353s_valid_emailxss-attack.html KAPDA New advisory Software: vBulletin Vendor: http://www.vBulletin.com Versions: 3.0.12-3.5.3 Class: Remote Status: Unpatched Exploit: Available Solution: Available Discovered by: imei addmimistrator Risk Level: Medium -------Description------- There is a security bug in most powerfull & common forum software vBulletin version 3.0.12&3.5.3 that allows attacker performe a XSS attack. -------Credit------- Discovered by: imei addmimistrator addmimistrator(4}gmail(O}com kapda(4}kapda(0)ir http://www.myimei.com http://myimei.com/security KAPDA - Computer Security Science Researchers Institute http://www.KAPDA.ir