:: vBspiders Professional Network ::

:: vBspiders Professional Network :: (http://www.vbspiders.com/vb/index.php)
-   قســم تطويــر المــــواقع (http://www.vbspiders.com/vb/f92.html)
-   -   [ خبـر ] : ثغرة جديده في هاك vBulletin Radio and TV Player (http://www.vbspiders.com/vb/t13709.html)

xman2 06-24-2009 04:30 PM

[ خبـر ] : ثغرة جديده في هاك vBulletin Radio and TV Player
 
السلام عليكم

تم وجود ثغرت جديده في نسخة من هاك
vBulletin Radio and TV Player

نرجوا ان تجدوا لنا ترقيع
هذا هو الدليل
رمز Code:
vBulletin Radio and TV Player Add-On (all version) - XSS , ****** injection and Redirect Vulnerability

About:-

Radio and TV Add-on will add a radio and TV library to your forum.

Features:-

- Users can add / delete / edit own stations

For more info about this plugin See - http://www.vbulletin.org/forum/showt...=152037&page=2

Note:-

- To exploit this Bug need to be registred!and after you are registered you can add new radio station
where name station can be ">
and URL ">


Poc: XSS

http://www.musicadigitale.net/forum/...php?station=92

Poc: ******

http://www.musicadigitale.net/forum/...php?station=93

Poc: Redirect

http://www.musicadigitale.net/forum/...php?station=94

dorks:- inurl:radioandtv.php

Bug founded by d3v1l [Avram Marius]

Date: 14.06.2009

# milw0rm.com [2009-06-15]
http://milw0rm.org/exploits/8965

وشكرااااا
تحياتي فريق الشركة العربية للحماية


الساعة الآن 05:35 PM


[ vBspiders.Com Network ]


SEO by vBSEO 3.6.0