Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Software PBLang 4.65 pmpshow.php XSS vulnerability

Subject: Software PBLang 4.65 pmpshow.php XSS vulnerability
Date: 23 Feb 2005 04:36:53 -0000


 [][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]  
 []  
 [] HRG - Hackerlounge Research Group 
 [] Release: HRG002 
 [] Friday 11-02-05  
 [] Software PBLang 4.65 pmpshow.php XSS 
vulnerability  
 []  
 [] The author can't be held responsible for any 
damage  
 [] done by a reader. You have your own resonsibility  
 [] Please use this document like it's meant to.  
 []  
 [][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]  
  
 Vulnerable: PBLang 4.65 (current) (and earlier?)  
  
  
 ---  
  
 General information:  
  
 PBLang is an international BBS-software based on 
PHP. It does not require any database but bases on a 
flatfile system. Many professional features. More 
info on the project website.  
  
  
 ---  
  
 Description:  
  
 pmpshow.php shows the pm's a user has received, 
however, the body of the received PM is not checked 
for any harmfull characters like < > and ". An 
attacker could steal sessions or do other things with 
javascript.  
  
  
 ---  
  
 Proof Of Concept:  
  
 Type "&lt;script 
language="javascript">alert("Hackerlounge.com pwns 
joo");&lt;/script&gt;" in the body of the PM your going to 
send a victim. An alertbox saying "Hcakerlounge.com 
pwns joo" should pop up.  
  
  
 ---  
  
 Fix and Vendor status:  
  
The vendor has been notified and a patch is 
"pending". 
  
  
 ---  
  
 [][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][]  
 []  
 [] HRG - Hackerlounge Research Group 
 [] Release: HRG002 
 [] Friday 11-02-05  
 [] Software PBLang 4.65 pmpshow.php XSS 
vulnerability  
 []  
 [] The author can't be held responsible for any 
damage  
 [] done by a reader. You have your own resonsibility  
 [] Please use this document like it's meant to.  
 []  
 [][][][][][][][][][][][][][][][][][][][][][][][][][]
[][][] 

<Prev in Thread] Current Thread [Next in Thread>
  • Software PBLang 4.65 pmpshow.php XSS vulnerability, Raven <=