Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12008
HistoryMar 29, 2006 - 12:00 a.m.

SQL-Injection and XSS in uTopsites 1.5.1

2006-03-2900:00:00
vulners.com
18

Advisory: SQL-Injection and XSS in uTopsites 1.5.1.

Уязвимый скрипт: index.php
Sql-injection:
http://www.listrank.com/index.php?do=out&id='22

Xss:
http://www.listrank.com/index.php?o=<script>alert()</script>&start=50
При добавлении комментариев не фильтруется ни одно поле. Пример:
"><script>alert()</script><"


Cyber Lords Team
www.cyberlords.net