Username: 
Password: 
Restrict session to IP 

XSS Found...

Global Rank: 1359
Totalscore: 18934
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 100d
vs4vijay`s Avatar

Last Seen: 10y 270d
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
hello there...
its me vijay From India....
there is XSS Flaw in The User's PM Section....
the Section Create folder has this Exploit....
Kindly Check that out...and Fix That...

Best Regards,
Vijay
I Would Love TO Change The World But They Wont Give Me The Source Code....
Global Rank: 215
Totalscore: 96581
Posts: 19
Thanks: 15
UpVotes: 8
Registered: 14y 346d



Last Seen: 266d 1h
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link

I confirm the XSS. Fun Smile
Global Rank: 252
Totalscore: 87258
Posts: 1644
Thanks: 1343
UpVotes: 894
Registered: 16y 123d




Last Seen: 3d 4h
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
Yep, can confirm it too Smile

But i think the bug is not exploitable, or almost impossible to exploit.

First you need a valid csrf token from a PM form, to create folders or see some success/error message.
Second, you can not access document.cookie in javascript for most browsers, as we set the HTTP-Only cookie option.

Will of course patch it when i have more time. (probably not before christmas)

Thanks for report!
Gizmore
The geeks shall inherit the properties and methods of object earth.
Global Rank: 1359
Totalscore: 18934
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 100d
vs4vijay`s Avatar

Last Seen: 10y 270d
The User is Offline
XSS Found...
Google/translate1Thank You!1Good Post!0Bad Post! link
yeah...
its okay...
i just wanna take ur notice about that....
cheers......
I Would Love TO Change The World But They Wont Give Me The Source Code....
tunelko, vs4vijay, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, kalungmas have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 2961 times.