about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Simple Machines Forum Size Tag HTML Injection Vulnerability


Title Simple Machines Forum Size Tag HTML Injection Vulnerability
Published 2004-05-05-12:00AM
Updated 2004-05-05-07:52PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  This vulnerability is credited to Cheng Peng Su <apple_soup@msn.com>.
Vulnerable  Simple Machines SMF 1.0 beta5p
Simple Machines SMF 1.0 beta4p
Simple Machines SMF 1.0 beta4.1
Not Vulnerable  
Code   No exploit is required for this issue, however Cheng Peng Su <apple_soup@msn.com> provided some proof-of-concept code.

An attacker could reportedly post content to the forums containing:

[size=expression(alert(document.cookie))]Content[/size]

With the limit that the forum software filters out quotes, apostrophes and semicolons.

Another method that circumvents the software filtering would be to post content such as:

[size=expression(eval(unescape(document.URL.substring(document.URL.length-34,document.URL.length))))]Content[/size]

then get the victim to follow:

http://www.example.com/index.php?topic=12345.0&alert('cookie: '+document.cookie)

Where the '12345.0' is the topic containing the previously posted content. The victim's browser would execute the last 34 characters (as specified in the previously posted 'length-34' content).
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 00:25:37 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
call of du www.nana3g www.dramaq maxcpm.inf free xxxvi 200 /compo Masala pho Www.freepo malayalamf joomla com www.trish curse Wap.Sexcom maxcpm.inf www.callgi shop580306 porno vide uhc.com xxxvidio szren.org www.fuda19 www.zyrjw. shop578888 www.wap.wa Panna maxcpm.inf gy20.cn www.trisha shop580388 167 www.bjdzd. video porn maxcpm.inf www.sex.br t895t ince Www.Gamelo 792103 Video gamb goodbye.as Hotbebs www.lierm. presstop news+for+c www.lierm. Guest.html memorable. germny sex Kuispu vid www.cbgggs