Previous Thread
Next Thread
Print Thread
Rate Thread
#318567 04/17/2010 5:57 PM
Joined: Apr 2010
Posts: 1
Lurker
Lurker
Offline
Joined: Apr 2010
Posts: 1
Hi All,

One of the users on my website is still using a leak in UBB to post images on pages using comments on the forum. When i look at what he posts to get the result i get the following:


Quote
[pic="http://i42.tinypic.com/2m4bqz4.gif" alt="a" style="position:fixed;right:0px;bottom:0px;float:right;" onmouseover="alert(String.fromCharCode(80,111,110,121,32,122,101,103,116,58,32,104,111,105));"]

Somehow he manages to run javascript with the above string. while the following:

#" onclick="alert(document.cookie)

is not working.

But when I try

Quote
[pic="http://i42.tinypic.com/2m4bqz4.gif" alt="a" style="position:fixed;right:0px;bottom:0px;float:right;" onmouseover="alert(String.fromCharCode(80,111,110,121,32,122,101,103,116,58,32,104,111,105));"]

myself I do not get the same result. So I guess when looking at his message some characters are not showing anymore. What exactly does he uses to be able to get javascript to run and how to prevent this from happening?


Sponsored Links
Joined: Jan 2000
Posts: 5,833
Likes: 20
UBBDev / UBBWiki Owner
Time Lord
UBBDev / UBBWiki Owner
Time Lord
Joined: Jan 2000
Posts: 5,833
Likes: 20
Well a BUG should be posted at UBBCentral, but "pic" isn't a default ubb tag... at least in a current version, so be sure to post the version of the UBB you're using.


UBB.Dev - Putting Dev into UBB.threads
Company: VNC Web Services - UBB.threads Scripts and Scripting, Install and Upgrade Services, Site and Server Maintenance.
Forums: A Gardeners Forum, Scouters World, and UGN Security
UBB.Threads: My UBB Themes, My UBB Scripts

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Gizmo
Gizmo
Portland, OR, USA
Posts: 5,833
Joined: January 2000
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)