Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability filter_list
Author
Message
vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability #1
In this tutorial I will be teaching you how to use XSS which is Cross Site Scripting to exploit a vBulletin forum. Please note that this only works with vBulletin 4.1.3, 4.1.4, and 4.1.5. Now, go to Google, and type in the code below:
Code:
inurl:/forums/admincp/plugin.php
Once you have found a site, you may notice that it says you need to log in. Just ignore it, you won't need to login for what we're doing. Now once at the site. Change http://example.com/forums/admincp/plugin.php to:
Code:
http://example.com/forums/admincp/plugin.php"><script>alert('Exploit Success!')</script>
Now, press enter!
If it is vulnerable, and you have exploited it successfully, you should see a pop-up that says Exploit Success!
That's all for this tutorial! If you run in to any problems PM me!

-Woody
(02-15-2012, 08:52 PM)Woody Wrote: The more you look, the more you find. The more you find, the more you look.

Reply

RE: vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability #2
Hi!
I've tried your method but I only saw the not found message.
Is that mean they fixed it or not ?

Reply

RE: vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability #3
(04-07-2012, 07:23 PM)lucashoang Wrote: Hi!
I've tried your method but I only saw the not found message.
Is that mean they fixed it or not ?

It means that the site is not vulnerable, so the site owner may have fixed it, or it may not be the right version.
(02-15-2012, 08:52 PM)Woody Wrote: The more you look, the more you find. The more you find, the more you look.

Reply