exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

MiniBB 3.1.1 Cross Site Scripting

MiniBB 3.1.1 Cross Site Scripting
Posted Nov 6, 2015
Authored by Tim Coen | Site curesec.com

MiniBB version 3.1.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 590b5e4c24559e2d96a7f6ac40e257ec083a0d641764cda9e643983399b53946

MiniBB 3.1.1 Cross Site Scripting

Change Mirror Download
Security Advisory - Curesec Research Team

1. Introduction

Affected Product: MiniBB 3.1.1
Fixed in: 3.2
Fixed Version Link: https://www.minibb.com/download.php?file=minibb
Vendor Contact: security@minibb.com
Vulnerability Type: XSS
Remote Exploitable: Yes
Reported to vendor: 09/01/2015
Disclosed to public: 10/07/2015
Release mode: Coordinated release
CVE: n/a
Credits Tim Coen of Curesec GmbH

2. Vulnerability Description

There is an XSS vulnerability in MiniBB 3.1.1. With this, it is possible to
steal cookies, bypass CSRF protection, or inject JavaScript keyloggers.

3. Proof of Concept


https://localhost/minibb/index.php?action=editmsg&topic=2&forum=1&post=3&page=1&anchor="><script>alert(1)</script>

4. Solution

To mitigate this issue please upgrade at least to version 3.2:

https://www.minibb.com/download.php?file=minibb

Please note that a newer version might already be available.

5. Report Timeline

09/01/2015 Informed Vendor about Issue
09/02/2015 Vendor announces release of fix
10/01/2015 No fix released yet, set new public disclosure date
10/01/2015 Vendor releases fix
10/07/2015 Disclosed to public


Blog Reference:
https://blog.curesec.com/article/blog/MiniBB-311-XSS-63.html


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close