‘Yabbse XSS Vulnerability in news_template.php’
Summary
‘YaBB SE is a PHP/MySQL port of the popular forum software YaBB (yet another bulletin board). A cross site scripting vulnerability in the product allows a remote attacker to cause the web page to insert malicious HTML and JavaScript into existing web pages.’
Credit:
‘The information has been provided by Mindwarper.’
Details
‘Vulnerable systems:
* Yabbse version 1.5.0
Example:
http://victim/yabbse/news_template.php?news_icon=<scr!pt>alert(document.cookie);</scr!pt>
Impact:
This can allow attackers to steal Yabb’s cookies from other users and hijack their accounts.’