[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    TangoBB 1.5.0-A3 XSS Vulnerability
From:       dennis.veninga () gmail ! com
Date:       2015-02-25 15:37:55
Message-ID: 201502251537.t1PFbtdo011910 () sf01web2 ! securityfocus ! com
[Download RAW message or body]

# Exploit Title: TangoBB 1.5.0-A3 XSS Vulnerability
# Google Dork: "Powered by TangoBB"
# Date: 24-2-2015
# Exploit Author: Dennis Veninga
# Vendor Homepage: https://github.com/Codetana/TangoBB
# Version: 1.5.0-A3
# Tested on: Firefox 36 & Chrome 38 / W8.1-x64
# CVE : NONE

Published:            24-2-2015
Vendor updated:        24-2-2015

TangoBB ->
Version:            1.5.0-A3
Date:                24-2-2015
Found By:            Dennis Veninga
Exploit info:        XSS Vulnerability
Dork:                "Powered by TangoBB"

XSS:
http://{target}/TangoBB/new.php/node/1

Affects: created topic, so an user can infect other users with malware and or take over their systems.
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic