Username: 
Password: 
Restrict session to IP 

XSS Found...

Global Rank: 1364
Totalscore: 18940
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 202d
vs4vijay`s Avatar

Last Seen: 11y 7d
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
hello there...
its me vijay From India....
there is XSS Flaw in The User's PM Section....
the Section Create folder has this Exploit....
Kindly Check that out...and Fix That...

Best Regards,
Vijay
I Would Love TO Change The World But They Wont Give Me The Source Code....
Global Rank: 214
Totalscore: 96585
Posts: 19
Thanks: 16
UpVotes: 9
Registered: 15y 83d



Last Seen: 1y 3d
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link

I confirm the XSS. Fun Smile
Global Rank: 248
Totalscore: 87961
Posts: 1662
Thanks: 1350
UpVotes: 906
Registered: 16y 225d




Last Seen: 7h 59m
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
Yep, can confirm it too Smile

But i think the bug is not exploitable, or almost impossible to exploit.

First you need a valid csrf token from a PM form, to create folders or see some success/error message.
Second, you can not access document.cookie in javascript for most browsers, as we set the HTTP-Only cookie option.

Will of course patch it when i have more time. (probably not before christmas)

Thanks for report!
Gizmore
The geeks shall inherit the properties and methods of object earth.
Global Rank: 1364
Totalscore: 18940
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 202d
vs4vijay`s Avatar

Last Seen: 11y 7d
The User is Offline
XSS Found...
Google/translate1Thank You!1Good Post!0Bad Post! link
yeah...
its okay...
i just wanna take ur notice about that....
cheers......
I Would Love TO Change The World But They Wont Give Me The Source Code....
tunelko, vs4vijay, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, kalungmas have subscribed to this thread and receive emails on new posts.
2 people are watching the thread at the moment.
This thread has been viewed 3064 times.