Praetorian503 Posted February 14, 2013 Report Posted February 14, 2013 Ultra Light Forum suffers from a persistent cross site scripting vulnerability.# Ultra Light Forum Persistant XSS Vulnerability# By cr4wl3r http://bastardlabs.info# http://bastardlabs.info/advisories/?id=86# Script: http://sourceforge.net/projects/ultralightforum/files/# Tested: Win 7Description :Ultra Light Forum developed in PHP and MySQL as a standalone forum with high speed, high user-friendliness.User can create, delete topic, can reply to others topic.The forum also comes with poll, where user can vote. To know more try UL Forum.Proof of Concept :Choose profile settings, and put the messages box with<script>alert(document.cookie)</script>And update your profileSo if any user can view you profile, the script will be executeDemo:http://bastardlabs.info/demo/ultraforum1.pnghttp://bastardlabs.info/demo/ultraforum2.pngSource: PacketStorm Quote