Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!

TUCoPS :: Web BBS :: Frequently Exploited :: web5480.htm

YaBB Cross-Site Scripting
24th Jun 2002 [SBWID-5480]

	YaBB Cross-Site Scripting


	YaBB 1 Gold SP1 and earlier versions


	In methodic [] advisory :


	When accessing a thread that doesn\'t exist, YaBB  will  give  an  error
	about the board not existing. Example:


	This will trigger an error in the CGI script and output the following:

	This topic doesn\'t exist on this board. NULL : 96.


	The problem here should be fairly obvious. By crafting  JavaScript  code
	in place of NULL, a malicious user can trick someone  into  running  the
	code of their choice,  since  YaBB  doesn\'t  filter  user  input/script

	 Exploit :




	Upgrade to a newer version of YaBB []

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH