![]() |
|
vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability (/Thread-vBulletin-4-1-3-4-1-4-and-4-1-5-XSS-Vulnerability) |
vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability - Woody - 03-19-2012 In this tutorial I will be teaching you how to use XSS which is Cross Site Scripting to exploit a vBulletin forum. Please note that this only works with vBulletin 4.1.3, 4.1.4, and 4.1.5. Now, go to Google, and type in the code below: Code: inurl:/forums/admincp/plugin.phpCode: http://example.com/forums/admincp/plugin.php"><script>alert('Exploit Success!')</script>If it is vulnerable, and you have exploited it successfully, you should see a pop-up that says Exploit Success! That's all for this tutorial! If you run in to any problems PM me! -Woody RE: vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability - lucashoang - 04-07-2012 Hi! I've tried your method but I only saw the not found message. Is that mean they fixed it or not ? RE: vBulletin 4.1.3, 4.1.4, and 4.1.5 XSS Vulnerability - Woody - 04-07-2012 (04-07-2012, 07:23 PM)lucashoang Wrote: Hi! It means that the site is not vulnerable, so the site owner may have fixed it, or it may not be the right version. |