| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | XSS - CMS Made Simple v1.0.2 |
| From: | "Curtis Zimmerman" <curtis.zimmerman@gmail.com> |
| Date: | Mon, 25 Dec 2006 18:13:33 -0300 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| Domainkey-signature: | a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=I+hOOUuoNEKw4PqfPc1YRaCDz3LOOknYnNDINnzkEWnPOOd6WBe989+yMordqPLCHjYJOzSBFCatTP1Rg37Ej0gbLkDhaXZDJsG+RSyo1ZiwFnwgC3bOLzHs1OeEFc3agaDS70Yitfcx0EP3XnXSHTpMwUmXediSFLDYdDTz8Sk= |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
Product: CMS Made Simple v1.0.2 Class: XSS Website: http://www.cmsmadesimple.org Found by: L0j1k of D.I.E. Inc. Googledork: "powered by cms made simple" -=-=-=-=- - Summary: Optional user comment module not properly sanitized for <script> tags. -=-=-=-=- - PoC: Input the following into user comment form: <script type="text/javascript">alert('XSS')</script> -=-=-=-=-=-=-=-=-=- More information can be found at: http://www.l0j1k.com/security/CMSMadeSimple_1.0.2_25Dec06.txt -=-=-=-=-=-=-=-=-=- Merry Christmas everyone! |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | HLStats Remote SQL Injection Exploit, nospam |
|---|---|
| Next by Date: | logahead UNU edition 1.0 Remote File Upload & code execution, corrado . liotta |
| Previous by Thread: | HLStats Remote SQL Injection Exploit, nospam |
| Next by Thread: | Re: XSS - CMS Made Simple v1.0.2, nanoymaster |
| Indexes: | [Date] [Thread] [Top] [All Lists] |