This is a writeup describing a Cross-Site Scripting (XSS) vulnerability in MySmartBB 1.0.0, where user input in the URI is not properly sanitized, allowing for the injection of malicious scripts. The document provides examples of vulnerable endpoints and basic exploitation steps.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:MySmartBB 1.0.0
No auth needed
Prerequisites:Access to a vulnerable MySmartBB 1.0.0 instance