The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
|
#1
|
|||
|
|||
![]()
A user on my forum turned me on to a BB code exploit. I'm using 4.2.2
A php script could be used to deliver a popup window simply by placing a link to it in the [ IMG ] tags. Upon opening the post or private message, the code is executed and the "victim" gets the popup prompt and displays their IP address (login credentials if the enter them). I tried the censor feature and blocked most of the common programming extensions but it's creating other issues. Does anyone have another idea that might work? Thanks. Here's an example (check the bb code): ![]() |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|