Ultra Light Forum Cross Site Scripting

2013.02.15
Credit: cr4wl3r
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

# Ultra Light Forum Persistant XSS Vulnerability # By cr4wl3r http://bastardlabs.info # http://bastardlabs.info/advisories/?id=86 # Script: http://sourceforge.net/projects/ultralightforum/files/ # Tested: Win 7 Description : Ultra Light Forum developed in PHP and MySQL as a standalone forum with high speed, high user-friendliness. User can create, delete topic, can reply to others topic. The forum also comes with poll, where user can vote. To know more try UL Forum. Proof of Concept : Choose profile settings, and put the messages box with <script>alert(document.cookie)</script> And update your profile So if any user can view you profile, the script will be execute Demo: http://bastardlabs.info/demo/ultraforum1.png http://bastardlabs.info/demo/ultraforum2.png

References:

http://bastardlabs.info/advisories/?id=86


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top