Full Disclosure mailing list archives

Re: home land tracker software


From: "Clint Bodungen" <clint () secureconsulting com>
Date: Fri, 6 Feb 2004 16:37:03 -0600

You misstyped your syntax... it should be:

<script>alert('secured!')</script>

But yes you are right.


----- Original Message ----- 
From: "Logan5" <Logan5 () Logan5 com>
To: <full-disclosure () lists netsys com>
Sent: Friday, February 06, 2004 3:06 PM
Subject: RE: [Full-disclosure] home land tracker software


LOL

The NAMECHECK dialog is succeptable to XSS.  Enter the following into
any of the fields:

<script>alert('secured!')</alert>

-L5


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: