跳转到帖子

游客您好,欢迎来到黑客世界论坛!您可以在这里进行注册。

赤队小组-代号1949(原CHT攻防小组)在这个瞬息万变的网络时代,我们保持初心,创造最好的社区来共同交流网络技术。您可以在论坛获取黑客攻防技巧与知识,您也可以加入我们的Telegram交流群 共同实时探讨交流。论坛禁止各种广告,请注册用户查看我们的使用与隐私策略,谢谢您的配合。小组成员可以获取论坛隐藏内容!

TheHackerWorld官方

MyBB Visual Editor 1.8.18 - Cross-Site Scripting

精选回复

发布于
# Title: MyBB Visual Editor 1.8.18 - Cross-Site Scripting
# Author: Numan OZDEMIR
# Vendor Homepage: mybb.com
# Software Link: https://mybb.com/download/
# Version: Up to v1.8.18. Fixed in v1.8.19.
# PoC Video: https://numanozdemir.com/mybb/xss.mp4
# CVE: CVE-2018-17128

# Description:
# Attacker can run JavaScript codes in victim user's browser while victim is replying a post.
# 'videotype' section causes this.

# How to Reproduce:

1)- Enter to thread posting page. (newthread.php, enter title and content.)
2)- Click "insert a video" command. Select any source and insert any URL.
3)- Edit the video source with your payload.
Or, directly add this code:

[video=PAYLOAD]http://victim.com[/video]
Example:
[video=PA<svg/onload=alert('xss')>YLOAD]http://victim.com[/video]

4)- Post the thread.

# While victim user replying your post, his browser will run JavaScript.
# Vulnerable pages: editpost.php, newreply.php, private.php
# and all Visual Editor embedded pages.
            

创建帐户或登录后发表意见

最近浏览 0

  • 没有会员查看此页面。