| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | Re: XSS - CMS Made Simple v1.0.2 |
| From: | nanoymaster@gmail.com |
| Date: | 28 Dec 2006 14:35:51 -0000 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
I can't remember if I posted another xss found (probably fond by someone else as well but I thought you might like to know) in the search box or url oyu can put xss eg. http://www.target.com/index.php?mact=Search%2Ccntnt01%2Cdosearch%2C0&cntnt01returnid=15&cntnt01searchinput="><script>alert('hi')</script>&cntnt01submit=Submit obviously this doesn't count for much as it is non permanent... but still enjoy NanoyMaster |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [SECURITY] [DSA 1242-1] New elog packages fix arbitrary code execution, Moritz Muehlenhoff |
|---|---|
| Next by Date: | [OpenPKG-SA-2006.044] OpenPKG Security Advisory (w3m), OpenPKG GmbH |
| Previous by Thread: | XSS - CMS Made Simple v1.0.2, Curtis Zimmerman |
| Next by Thread: | logahead UNU edition 1.0 Remote File Upload & code execution, corrado . liotta |
| Indexes: | [Date] [Thread] [Top] [All Lists] |