|
|
| |
| ProBoards is a popular online message board service. An XSS vulnerability allowed users to inject JavaScript into an [img] tag before it was fixed on November the 28th. |
| |
Credit:
The information has been provided by Danny Chia.
|
| |
Example:
If you posted this:
[img]http://a.a/a"onerror="javascript:alert(document.cookie)[/img]
A user viewing the post would see a popup message containing his cookie.
Vendor status:
Vendor was notified and the vulnerability was fixed almost immediately.
|
|
|