Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:24866
HistoryOct 11, 2010 - 12:00 a.m.

OverLook Cross-site Scripting Vulnerability

2010-10-1100:00:00
vulners.com
39

ANATOLIA SECURITY ADVISORY

ADVISORY INFO

VULNERABLE PRODUCT

VULNERABILITY DETAILS

  • Description: "title.php" gets "frame" parameter with sqgetGlobalVar function. sqgetGlobalVar function apply decodeHTML function to variable. This function decode
    HTML tags so its make a chance to succesfull exploitation with some browser (e.g. Mozilla Firefox encodes HTML tags). After that application include "frame"
    variable into inline javascript code.

  • Exploit/POC: http://www.anatoliasecurity.com/exploits/overlook-xss-poc.txt