TUCoPS :: Web BBS :: etc :: bt638.txt

Splatt Forum html injection code in post icon

Any user can inject html code when create a new post.

The bug are in the post icon:

<img src="icon.gif" etc.>

If you create a personalized form with this code:



the final code of the post icon is:



tag="" etc.>

The exploit form is here:

by Lethal Lab (Lethalman)

