The_Arhitect Posted May 22, 2012 Report Posted May 22, 2012 Vanilla FirstLastNames 1.3.2 Plugin Persistant XSS# Title: Vanilla FirstLastNames 1.3.2 Plugin Persistant XSS Vulnerability# Date: 18/5/12# Author: Henry Hoggard# Author URL: henryhoggard.co.uk# Author Twitter: @henryhoggard# Software: Vanilla Version 2.0.18.4 + FirstLastNames 1.3.2http://vanillaforums.org/addon/firstlastnames-plugin# http://vanillaforums.org#############################################################On Edit your account enter your XSS String in either the first name or last name field.Then if a user visits your page the XSS will execute.http://target.tld/index.php?p=/profile/myprofile/1/userXSS:<script>alert('x')</script>#############################################################http://henryhoggard.co.ukSursa: Vanilla FirstLastNames 1.3.2 Plugin Persistant XSS Quote