Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Software PBLang 4.65 pmpshow.php XSS vulnerability |
|---|---|
| Date: | 23 Feb 2005 04:36:53 -0000 |
[][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]
[]
[] HRG - Hackerlounge Research Group
[] Release: HRG002
[] Friday 11-02-05
[] Software PBLang 4.65 pmpshow.php XSS
vulnerability
[]
[] The author can't be held responsible for any
damage
[] done by a reader. You have your own resonsibility
[] Please use this document like it's meant to.
[]
[][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]
Vulnerable: PBLang 4.65 (current) (and earlier?)
---
General information:
PBLang is an international BBS-software based on
PHP. It does not require any database but bases on a
flatfile system. Many professional features. More
info on the project website.
---
Description:
pmpshow.php shows the pm's a user has received,
however, the body of the received PM is not checked
for any harmfull characters like < > and ". An
attacker could steal sessions or do other things with
javascript.
---
Proof Of Concept:
Type "<script
language="javascript">alert("Hackerlounge.com pwns
joo");</script>" in the body of the PM your going to
send a victim. An alertbox saying "Hcakerlounge.com
pwns joo" should pop up.
---
Fix and Vendor status:
The vendor has been notified and a patch is
"pending".
---
[][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]
[]
[] HRG - Hackerlounge Research Group
[] Release: HRG002
[] Friday 11-02-05
[] Software PBLang 4.65 pmpshow.php XSS
vulnerability
[]
[] The author can't be held responsible for any
damage
[] done by a reader. You have your own resonsibility
[] Please use this document like it's meant to.
[]
[][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Software PBLang 4.65 search.php XSS vulnerability, Raven |
|---|---|
| Next by Date: | Software PBLang 4.65 pm.php XSS vulnerability, Raven |
| Previous by Thread: | Software PBLang 4.65 search.php XSS vulnerability, Raven |
| Next by Thread: | Software PBLang 4.65 pm.php XSS vulnerability, Raven |
| Indexes: | [Date] [Thread] [Top] [All Lists] |