exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

MiniBB 3.1.1 Cross Site Scripting

MiniBB 3.1.1 Cross Site Scripting
Posted Nov 6, 2015
Authored by Tim Coen | Site curesec.com

MiniBB version 3.1.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 590b5e4c24559e2d96a7f6ac40e257ec083a0d641764cda9e643983399b53946

MiniBB 3.1.1 Cross Site Scripting

Change Mirror Download
Security Advisory - Curesec Research Team

1. Introduction

Affected Product: MiniBB 3.1.1
Fixed in: 3.2
Fixed Version Link: http://www.minibb.com/download.php?file=minibb
Vendor Contact: security@minibb.com
Vulnerability Type: XSS
Remote Exploitable: Yes
Reported to vendor: 09/01/2015
Disclosed to public: 10/07/2015
Release mode: Coordinated release
CVE: n/a
Credits Tim Coen of Curesec GmbH

2. Vulnerability Description

There is an XSS vulnerability in MiniBB 3.1.1. With this, it is possible to
steal cookies, bypass CSRF protection, or inject JavaScript keyloggers.

3. Proof of Concept


http://localhost/minibb/index.php?action=editmsg&topic=2&forum=1&post=3&page=1&anchor="><script>alert(1)</script>

4. Solution

To mitigate this issue please upgrade at least to version 3.2:

http://www.minibb.com/download.php?file=minibb

Please note that a newer version might already be available.

5. Report Timeline

09/01/2015 Informed Vendor about Issue
09/02/2015 Vendor announces release of fix
10/01/2015 No fix released yet, set new public disclosure date
10/01/2015 Vendor releases fix
10/07/2015 Disclosed to public


Blog Reference:
http://blog.curesec.com/article/blog/MiniBB-311-XSS-63.html


Login or Register to add favorites

File Archive:

November 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    16 Files
  • 2
    Nov 2nd
    17 Files
  • 3
    Nov 3rd
    17 Files
  • 4
    Nov 4th
    11 Files
  • 5
    Nov 5th
    0 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    3 Files
  • 8
    Nov 8th
    59 Files
  • 9
    Nov 9th
    12 Files
  • 10
    Nov 10th
    6 Files
  • 11
    Nov 11th
    11 Files
  • 12
    Nov 12th
    1 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    9 Files
  • 15
    Nov 15th
    33 Files
  • 16
    Nov 16th
    53 Files
  • 17
    Nov 17th
    11 Files
  • 18
    Nov 18th
    14 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    26 Files
  • 22
    Nov 22nd
    22 Files
  • 23
    Nov 23rd
    10 Files
  • 24
    Nov 24th
    9 Files
  • 25
    Nov 25th
    11 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    20 Files
  • 29
    Nov 29th
    9 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close