Username: 
Password: 
Restrict session to IP 

XSS Found...

Global Rank: 1352
Totalscore: 18932
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 41d
vs4vijay`s Avatar

Last Seen: 10y 210d
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
hello there...
its me vijay From India....
there is XSS Flaw in The User's PM Section....
the Section Create folder has this Exploit....
Kindly Check that out...and Fix That...

Best Regards,
Vijay
I Would Love TO Change The World But They Wont Give Me The Source Code....
Global Rank: 216
Totalscore: 96583
Posts: 19
Thanks: 15
UpVotes: 8
Registered: 14y 287d



Last Seen: 206d 21h
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link

I confirm the XSS. Fun Smile
Global Rank: 253
Totalscore: 87267
Posts: 1636
Thanks: 1338
UpVotes: 886
Registered: 16y 64d




Last Seen: 17h 53m
The User is Offline
XSS Found...
Google/translate1Thank You!0Good Post!1Bad Post! link
Yep, can confirm it too Smile

But i think the bug is not exploitable, or almost impossible to exploit.

First you need a valid csrf token from a PM form, to create folders or see some success/error message.
Second, you can not access document.cookie in javascript for most browsers, as we set the HTTP-Only cookie option.

Will of course patch it when i have more time. (probably not before christmas)

Thanks for report!
Gizmore
The geeks shall inherit the properties and methods of object earth.
Global Rank: 1352
Totalscore: 18932
Posts: 18
Thanks: 18
UpVotes: 15
Registered: 15y 41d
vs4vijay`s Avatar

Last Seen: 10y 210d
The User is Offline
XSS Found...
Google/translate1Thank You!1Good Post!0Bad Post! link
yeah...
its okay...
i just wanna take ur notice about that....
cheers......
I Would Love TO Change The World But They Wont Give Me The Source Code....
tunelko, vs4vijay, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, JanLitwin17, SwolloW, dangarbri have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 2921 times.