AOH :: HP Unsorted V :: BU-1720.HTM

Tagcloud for DataLife Engine vulnerability
Vulnerability in Tagcloud for DataLife Engine
Vulnerability in Tagcloud for DataLife Engine

Hello Bugtraq!

I want to warn you about Cross-Site Scripting vulnerability in Tagcloud
plugin for DataLife Engine (DLE). Which I found at 07.01.2010.

It is similar to XSS vulnerability in 3D Cloud for Joomla
( About millions of flash files 
tagcloud.swf which are vulnerable to XSS attacks I mentioned in my article
XSS vulnerabilities in 34 millions flash files



Code will execute after click. It's strictly social XSS.

Also it's possible to conduct HTML Injection attack, including in those
flash files which have protection (in flash files or via WAF) against
javascript and vbscript URI in parameter tagcloud.

HTML Injection:


Vulnerable are all versions of Tagcloud plugin.

I mentioned about this vulnerability at my site

Best wishes & regards,
Administrator of Websecurity web site 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH
We do not send spam. If you have received spam bearing an email address, please forward it with full headers to