[36539] in bugtraq

home help back first fref pref prev next nref lref last post

www.proboards.com / YaBB XSS Vuln

daemon@ATHENA.MIT.EDU (admin@leetflash.com)
Fri Sep 17 01:15:00 2004

Date: 15 Sep 2004 23:12:42 -0000
Message-ID: <20040915231242.3251.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <admin@leetflash.com>
To: bugtraq@securityfocus.com



A Cross Site scripting vulnerability exists currently for all boards of the ever popular www.proboards.com which has code based off of the popular YaBB Forums.

This can result in an attacker stealing users Cookie Information and possible defacing/hijacking of the message board and its users accounts on the message board.

The following code can be used to execute this XSS vuln:

http://WEBSITE/index.cgi?board=[BOARDNAME]&action=display&num=[VALID TOPIC NUMBER]&">&lt;script&gt;alert(document.cookie);&lt;/script&gt;

Be Cautious of suspicous looking links.

##################################
# -LJ Lemke  leetflash@yahoo.com #
##################################

home help back first fref pref prev next nref lref last post