--------------------------------- XSS in Vbulletin 3.6.0 in IE 0nly --------------------------------- Author: Stefan Email: stefan@dakotacom.net Group: EnigmaGroup --------------------------------- Vulnerable: vbulletin 3.5.4 in IE Vulnerable: vbulletin 3.6.0 in IE --------------------------------- Javascript may be executed by saving code as .pdf and uploading as attachment.This only works in IE
На милворме есть демонстарция похищения кукиса с помощью xxs ( http://milw0rm.com/video/ ) - трафик 24 мб если что