Exploit XMB Forum 1.6 pre-beta - Image Tag Script Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21300
Проверка EDB
  1. Пройдено
Автор
SKIZZIK
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2002-0316
Дата публикации
2002-02-22
Код:
source: https://www.securityfocus.com/bid/4167/info

The Extreme Message Board (XMB) 1.6 Magic Lantern pre-beta version reportedly allows JavaScript and HTML to be entered in messages. This can be achieved by entering script or HTML between [img] and [/img] tags in a forum message.

This has been fixed in the 1.6 Magic Lantern final beta version of XMB. 

[img]javasCript:alert('Hello world.')[/img]
 
Источник
www.exploit-db.com

Похожие темы