|
|
| |
| Facebook Profile MyBB Plugin 2.4 suffers from persistant cross-site scripting vulnerability. |
| |
Credit:
The information has been provided by limb0.
|
| |
Vulnerable Systems:
* Facebook Profile MyBB Plugin 2.4
Installation:
1. Upload all folder to your MyBB installation directory.
2. Go to your Admin-CP and click Plugins.
3. Click Install & Activate.
Configuration:
User-CP >> Edit Profile >> Facebook id/nickname >> Type: "><script>alert(/limb0/)</script>
Then visit one of your threads,and voila.
Proofs:
Configuration:http://postimage.org/image/sumvqlro7/
Testing:http://postimage.org/image/57tjltqb9/
-------------------------------Vulnerable Code---------------------------------------
Line 200-216
$post["iconfacebook"] = '<a href="http://www.facebook.com/' . $post["facebook"] .'" TARGET=_BLANK><img src="'.$mybb->settings['bburl'].'/images/facebook.gif' .'" /></a>';
} else
{
}
} else {
$post["iconfacebook"] = '<a href="http://www.facebook.com/' . $post["facebook"] .'" TARGET=_BLANK><img src="'.$mybb->settings['bburl'].'/images/facebook.gif' .'" /></a>';
}
}
Disclosure Timeline:
Published: 2012-12-13
|
|
blog comments powered by
|