Lucene search

K
exploitdbSkizzikEDB-ID:21300
HistoryFeb 22, 2002 - 12:00 a.m.

XMB Forum 1.6 pre-beta - Image Tag Script Injection

2002-02-2200:00:00
skizzik
www.exploit-db.com
69

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/4167/info

The Extreme Message Board (XMB) 1.6 Magic Lantern pre-beta version reportedly allows JavaScript and HTML to be entered in messages. This can be achieved by entering script or HTML between [img] and [/img] tags in a forum message.

This has been fixed in the 1.6 Magic Lantern final beta version of XMB. 

[img]javasCript:alert('Hello world.')[/img] 

AI Score

7.4

Confidence

Low

Related for EDB-ID:21300