‘Yabbse XSS Vulnerability in news_template.php’

Summary

YaBB SE is a PHP/MySQL port of the popular forum software YaBB (yet another bulletin board). A cross site scripting vulnerability in the product allows a remote attacker to cause the web page to insert malicious HTML and JavaScript into existing web pages.’

Credit:

‘The information has been provided by Mindwarper.’


Details

Vulnerable systems:
 * Yabbse version 1.5.0

Example:
http://victim/yabbse/news_template.php?news_icon=<scr!pt>alert(document.cookie);</scr!pt>

Impact:
This can allow attackers to steal Yabb’s cookies from other users and hijack their accounts.’

Categories: UNIX