| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060606002740.12029.qmail@securityfocus.com>
Date: 6 Jun 2006 00:27:40 -0000
From: luny@...fucktard.com
To: bugtraq@...urityfocus.com
Subject: ParticleSoft Wiki v1.0.2
ParticleSoft Wiki v1.0.2
Effected files:
input boxes on editing pages:
XSS Proof of concept:
We notice br tags are allowed, so by using a STYLE attribute using a comment to break up expression we can create a XSS vuln:
Put the following in when editing a page:
<br IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))">
Thanks to Rsnake & Roman Ivanov for the above xss example code.