vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability 03-19-2012, 07:21 PM
#1
In this tutorial I will be teaching you how to use XSS which is Cross Site Scripting to exploit a vBulletin forum. Please note that this only works with vBulletin 4.1.3, 4.1.4, and 4.1.5. Now, go to Google, and type in the code below:
Once you have found a site, you may notice that it says you need to log in. Just ignore it, you won't need to login for what we're doing. Now once at the site. Change http://example.com/forums/admincp/plugin.php to:
Now, press enter!
If it is vulnerable, and you have exploited it successfully, you should see a pop-up that says Exploit Success!
That's all for this tutorial! If you run in to any problems PM me!
-Woody
Code:
inurl:/forums/admincp/plugin.phpCode:
http://example.com/forums/admincp/plugin.php"><script>alert('Exploit Success!')</script>If it is vulnerable, and you have exploited it successfully, you should see a pop-up that says Exploit Success!
That's all for this tutorial! If you run in to any problems PM me!
-Woody

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)