Pagine: [1]
Stampa
Autore Discussione: Permanent Xss Upb <= 1.96  (Letto 468 volte)
Matrix86
Amministratore
Full Member
*****

Popolarità: +7/-0
Scollegato Scollegato

Messaggi: 133



WWW
« inserito:: Settembre 22, 2008, 09:46:04 »

Citazione
Respect for Rgod...R.I.P my master!

AUTHOR :
   Matrix86
Contact:
   matrix86 [AT ] tuxmealux [ DOT] net

Found Permanent Xss in:
   /profile.php
   /viewtopic.php

Vulnerability info:
   Line: 673
   Code: $msg = preg_replace("/\[img\]http://(.*?)\[\/img\]/si", "<img src=\"\\1\" border=\"0\">", $msg);


Description:
   The UPB doesn't clean the signature from quotes and javascript codes. An attacker can insert a maliciuos js code (using BB code) to grab cookie data or another evil actions.

Example:
   Insert this into the signature:
Codice:
[IMG]/upb/images/avatars/scooby.gif" OnLoad="alert(1)"[/img]

Fix:
   To fix this you can check data on insert time to delete js code, or use htmlentities().
   Good Work.
« Ultima modifica: Febbraio 22, 2011, 18:54:21 da Matrix86 » Registrato


Pagine: [1]
Stampa
 
Vai a: