Bugtraq mailing list archives

PhpBB Xs 2 profile.php Permanent Xss Vulnerability


From: h3llcode () hotmail it
Date: 20 Sep 2007 16:35:14 -0000

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

PhpBB Xs 2 profile.php Permanent Xss Vulnerability

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

#Found By Seph1roth    

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

[POST METHOD]

Corrupted page: profile.php?mode=editprofile&cpl_mode=profile_info

Bugged Variable: "selfdes" (Campo "Altre informazioni")

Xss: </textarea>[XSS STRING]


Current thread: