XMB "U2U Instant Messenger" Cross-Site Scripting

Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 3.5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 6.8/10
Exploit range: Remote
Attack complexity: Medium
Authentication: Single time
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

#Aria-Security Team #http://Aria-Security.com #Contact: Advisory (at) aria-security (dot) com [email concealed] #Type:Remote Cross-Site Scripting #Article on XSS: http://aria-security.net/xss.rar #Discovered By Aria-Security Team #Software: XMB U2u Instant Messenger # #Explanation: First of all user must be REGISTERED - Go to http://target/xmbpath/memcp.php ---> U2U Instant Messenger - Inster your xss code for the recipient - Press Preview Original Advisory http://aria-security.com/forum/showthread.php?p=129

