MyBB Thread Redirect 0.2.1 Cross Site Scripting ≈ Packet Storm – Digitalmunition




Exploit/Advisories no-image-featured-image.png

Published on February 4th, 2021 📆 | 3113 Views ⚑

0

MyBB Thread Redirect 0.2.1 Cross Site Scripting ≈ Packet Storm

MyBB Thread Redirect 0.2.1 Cross Site Scripting
Posted Feb 1, 2021
Authored by 0xB9

MyBB Thread Redirect plugin version 0.2.1 suffers from a cross site scripting vulnerability.

tags | exploit, xss
MD5 | 05e67e18d45785761cd520d48cd42fba
# Exploit Title: MyBB Thread Redirect Plugin 0.2.1 - Cross-Site Scripting
# Date: 7/23/2018
# Author: 0xB9
# Software Link: https://github.com/jamiesage123/Thread-Redirect
# Version: 0.2.1
# Tested on: Windows 10

1. Description:
This plugin allows threads to redirect to a URL with optional custom text. The custom text input is vulnerable to Cross-Site Scripting.

2. Proof of Concept:

- Create a new thread
- Input any Thread Subject and Redirect URL you'd like
- Use the following payload for Your Message
Anyone who views the thread will execute payload.

Source link

Tagged with:



Leave a Reply