This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
> MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, | |
> which makes it easier for remote attackers to conduct redirection attacks. | |
> | |
> ------------------------------------------ | |
> | |
> [Additional Information] | |
> is parsing link with target="_blank" rel="noopener" | |
> <a class=mycode_url href=malicious.html target="_blank" rel="noopener"> malicious.html </a> MyBB users with Microsoft Edge browser are vulnerable for this attack | |
> | |
> ------------------------------------------ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
> /goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 | |
> 2017" firmware has Unauthenticated Stored Cross Site Scripting via the | |
> lang parameter. | |
> | |
> ------------------------------------------ | |
> | |
> [Additional Information] | |
> Below find the Vulnerable POST request | |
> | |
> POST /goform/setLang HTTP/1.1 |