GOOGLE HACKING TRICKS, LEARN SECRETS OF HACKING

Output Index Script

“Powered by: vBulletin * 3.0.1″ inurl:newreply.php

Posted by Zul Afdal - -

vBulletin is a customizable forums package for web sites. It has been written in PHP and is complimented with MySQL. While a user is previewing the post, both newreply.php and newthread.php correctly sanitize the input in ‘Preview’, but not Edit-panel. Malicious code can be injected by an attacker through this flaw. More information at http://www.securityfocus.com/bid/10612/.

Google Search: “Powered by: vBulletin * 3.0.1″ inurl:newreply.php