Search This Blog

Powered by Blogger.

Blog Archive

Labels

XSS vulnerability in vBulletin 3.8.x - 4.1.11

GreyHat hackers Sony and Flexxpoint has discovered Reflected and Persistent XSS Vulnerability found in Vbulletin forum software, one of the famous and most powerful forum software. Hacker claimed that he found xss vulnerability in VBulletin 3.8.x - 4.1.11 .

Hacker have discovered XSS vulnerability in lot of places including '/forum/blog.php' ,'forum/group.php' pages in Vbulletin official websites.


Also hackers found persistent XSS vulnerability in chinclub.ru. They tested this vulnerability in other forums also.They tested this vulnerability in Demo vBulletin Forum. Version 4.1.10.(https://www.vbulletin.com/admindemo.php). Hacker said It's Work in other version too.


Hacker also provide us a simple POC video:


Also Another Hacker ".eof" discovered and published a POC for the xss vulnerability in vbulletin board lastmonth.
Share it:

Breaking News

Vulnerability

Web Application Vulnerability

XSS Vulnerability