Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
vbulletin < 3.6.6 [permanent xss]

Date: Wed May 16 2007 - 09:12:32 CDT

vendor site:http://www.vbulletin.com/
product:vbulletin < 3.6.6
bug: permanent xss
affected file: calendar.php
risk : medium

xss permanent ( must be loggued ) PoC :
--> fill up the title field with :

Event Date : ( some far away date ... like 2010 for exemple )
message : whatever .

when it's done look at the :"Request Reminder for this Event" link.
(it looks like this:
if you click,your XSS will be executed .

permanent xss are dangerous ...
see : http://en.wikipedia.org/wiki/Cross_site_scripting

regards laurent gaffié
contact: laurent.gaffie[at]g/**/m/**/a/**/i/**/l.com