Full Disclosure mailing list archives

Re: xss in blackboard 8


From: dave b <db.pub.mail () gmail com>
Date: Sun, 17 Oct 2010 23:40:58 +1100

Woops the system Learning System - CE Enterprise License (Release CE
8.0.4)  I was testing on was originally 6.X something and got upgraded
so my (testing) previous posts still existed :/

In any-case here is an xss against firefox 3 that works against
Release CE 8.0.4:
<b><script<b></b><alert(1)</script </b>

--
How apt the poor are to be proud.               -- William Shakespeare, "Twelfth-Night"

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: