Форумы vBulletin Version 3.6.0

Discussion in 'Уязвимости CMS/форумов' started by Dimazzz, 2 Sep 2006.

  1. Dimazzz

    Dimazzz Elder - Старейшина

    Joined:
    22 Nov 2005
    Messages:
    172
    Likes Received:
    19
    Reputations:
    1
    Вроде последний , кто нить нарыл про него что нибуть?
     
  2. _-[A.M.D]HiM@S-_

    _-[A.M.D]HiM@S-_ Green member

    Joined:
    28 Dec 2005
    Messages:
    441
    Likes Received:
    454
    Reputations:
    696
    ---------------------------------
    XSS in Vbulletin 3.6.0 in IE 0nly
    ---------------------------------
    Author: Stefan
    Email: stefan@dakotacom.net
    Group: EnigmaGroup
    ---------------------------------
    Vulnerable: vbulletin 3.5.4 in IE
    Vulnerable: vbulletin 3.6.0 in IE
    ---------------------------------
    Javascript may be executed by
    saving code as .pdf and uploading
    as attachment.This only works in IE
     
  3. gemaglabin

    gemaglabin Green member

    Joined:
    1 Aug 2006
    Messages:
    772
    Likes Received:
    842
    Reputations:
    1,369
    На милворме есть демонстарция похищения кукиса с помощью xxs ( http://milw0rm.com/video/ ) - трафик 24 мб если что
     
  4. Dimazzz

    Dimazzz Elder - Старейшина

    Joined:
    22 Nov 2005
    Messages:
    172
    Likes Received:
    19
    Reputations:
    1
    ? это
     
  5. Dimazzz

    Dimazzz Elder - Старейшина

    Joined:
    22 Nov 2005
    Messages:
    172
    Likes Received:
    19
    Reputations:
    1
    Долго однако на Диалапе =(