Full Disclosure mailing list archives

Re: VHCS 2.x HTTP Error Cross Site Scripting


From: InfoSecBOFH <infosecbofh () gmail com>
Date: Thu, 24 Nov 2005 02:27:24 -0800

Cool... so give me a real world attack scenario with this....

On 11/23/05, Moritz Naumann <info () moritz-naumann com> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Moritz Naumann wrote:

SOLUTIONS Moritz Naumann IT Consulting & Services has crafted a
unified diff patch against VHCS 2.4.6.2 which is available at
http://moritz-naumann.com/adv/0006/vhcsxss/patch/index.php.diff

This patch had been lost during an upload. It's back, now.

Moritz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDhTZin6GkvSd/BgwRAkx8AJ43RauRSIke/U6GoZA3/4d7rLo2ogCfVcvY
n9zvyiQnzV5Doqn8tsNMrbo=
=Qfzc
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: