Username: 
Password: 
Restrict session to IP 

XSS Found...

Global Rank: 1374
Totalscore: 18939
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 268d
vs4vijay`s Avatar

Last Seen: 11y 73d
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
hello there...
its me vijay From India....
there is XSS Flaw in The User's PM Section....
the Section Create folder has this Exploit....
Kindly Check that out...and Fix That...

Best Regards,
Vijay
I Would Love TO Change The World But They Wont Give Me The Source Code....
Global Rank: 213
Totalscore: 96594
Posts: 19
Thanks: 16
UpVotes: 9
Registered: 15y 150d



Last Seen: 1y 69d
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link

I confirm the XSS. Fun Smile
Global Rank: 227
Totalscore: 94362
Posts: 1680
Thanks: 1358
UpVotes: 920
Registered: 16y 292d




Last Seen: 7d 15h
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
Yep, can confirm it too Smile

But i think the bug is not exploitable, or almost impossible to exploit.

First you need a valid csrf token from a PM form, to create folders or see some success/error message.
Second, you can not access document.cookie in javascript for most browsers, as we set the HTTP-Only cookie option.

Will of course patch it when i have more time. (probably not before christmas)

Thanks for report!
Gizmore
The geeks shall inherit the properties and methods of object earth.
Global Rank: 1374
Totalscore: 18939
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 268d
vs4vijay`s Avatar

Last Seen: 11y 73d
The User is Offline
XSS Found...
Google/translate1Thank You!1Good Post!0Bad Post! link
yeah...
its okay...
i just wanna take ur notice about that....
cheers......
I Would Love TO Change The World But They Wont Give Me The Source Code....
tunelko, vs4vijay, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, csuquvq have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 3104 times.