Full Disclosure mailing list archives
Re: Geeklog <= v1.6.0sr2 - Remote File Upload
From: Andrew Farmer <andfarm () gmail com>
Date: Sun, 4 Oct 2009 12:22:59 -0700
On 4 Oct 2009, at 08:47, Jaloh Smith wrote:
The easy one is when the forum allows anonymous posts and is configured for text posts. The anonymous user name is never filtered, so you can put anything there, including a reference to the javascript uploaded as the user profile image.. <script src="../images/userphotos/username.jpg"></script>
That's actually a much worse exploit than the file upload. There's no reason the script you load has to be stored locally -- it works just as well if you pull it from another domain. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Geeklog <= v1.6.0sr2 - Remote File Upload Jaloh Smith (Oct 02)
- Re: Geeklog <= v1.6.0sr2 - Remote File Upload darky (Oct 03)
- Re: Geeklog <= v1.6.0sr2 - Remote File Upload Jaloh Smith (Oct 04)
- Re: Geeklog <= v1.6.0sr2 - Remote File Upload Andrew Farmer (Oct 04)
- Re: Geeklog <= v1.6.0sr2 - Remote File Upload Jaloh Smith (Oct 04)
- Re: Geeklog <= v1.6.0sr2 - Remote File Upload darky (Oct 03)