TUCoPS :: Web BBS :: Frequently Exploited :: tb10917.htm

vbulletin < 3.6.6
vbulletin < 3.6.6
vbulletin < 3.6.6



vendor site:http://www.vbulletin.com/ 
product:vbulletin < 3.6.6
bug: permanent xss
affected file: calendar.php
risk : medium

xss permanent ( must be loggued ) PoC :
http://127.0.0.1/vbulletin/calendar.php?do=add&type=single&c=1 
--> fill up the title field with : 
 

Event Date : ( some far away date ... like 2010 for exemple )
message : whatever .

when it's done look at the :"Request Reminder for this Event" link.
(it looks like this: http://127.0.0.1/vbulletin/calendar.php?do=addreminder&e=2) 
if you click,your XSS will be executed .


reminder:
permanent xss are dangerous ...
see : http://en.wikipedia.org/wiki/Cross_site_scripting 

regards laurent gaffi=E9 
contact: laurent.gaffie[at]g/**/m/**/a/**/i/**/l.com

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH