header-logo
Suggest Exploit
vendor:
Simple Forum PHP
by:
arnab_s
4,3
CVSS
MEDIUM
XSS/HTML Injection
79
CWE
Product Name: Simple Forum PHP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Simple Forum PHP (XSS/HTML Injection Vulnerabilities)

A vulnerability was found in the Simple Forum PHP software, which allows attackers to insert HTML/JavaScript codes into the http://server/demo_guestbook.php?act=new page. This vulnerability works if the Approval option on http://www.simpleforumphp.com/demo_forum.php act=topic_options is not checked.

Mitigation:

Ensure that the Approval option on http://www.simpleforumphp.com/demo_forum.php act=topic_options is checked.
Source

Exploit-DB raw data:

# Exploit Title: Simple Forum PHP (XSS/HTML Injection Vulnerabilities)
# Date: August 25, 2010
# Author: arnab_s
# Software Link: http://www.simpleforumphp.com/forum/admin.php?act=topic_options
# Price: $24.99

found bug on:

http://server/demo_guestbook.php?act=new

details:

you can insert html/javascript codes. works if Approval option on
http://www.simpleforumphp.com/demo_forum.php act=topic_options were
not checked.