Train

PDA

توجه ! این یک نسخه آرشیو شده میباشد و در این حالت شما عکسی را مشاهده نمیکنید برای مشاهده کامل متن و عکسها بر روی لینک مقابل کلیک کنید : Invision Power Board v1.3 Final Cross Site Scripting Vulnerabillity


Behrooz_Ice
03-08-2004, 10:26 PM
Invision Power Board is available under a yearly and lifetime purchase option for both personal and commercial use, no catches, no "spyware", no hidden costs anywhere. The Vulnerabillity is Cross Site Scripting. The vulnerable form fields are "c","f","showtopic","showuser","username". If an attacker will request the following url from the server. Enjoy!