lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 28 Sep 2010 20:23:19 +0200
From: Yam Mesicka <yammesicka@...il.com>
To: bugtraq <bugtraq@...urityfocus.com>
Subject: Fwd: 2.6.6 <= phpMyFAQ <= 2.6.8 XSS

Hi,

My name is Yam Mesicka, I'm from Israel and this is my first big
disclosure (so help needed is here :-)
I found XSS on phpMyFAQ system, versions 2.6.6 to 2.6.8.

Dork: intitle:"Powered By phpMyFAQ 2.6.8"
XSS: site-location/index.php/"><script>alert("XSS")</script>
Vul: 2.6.6 <= phpMyFAQ <= 2.6.8

The problem has been fixed on phpMyFAQ 2.6.9.

Advisory here: http://www.phpmyfaq.de/advisory_2010-09-28.php

If more details are needed, please contact me.
- Yam Mesicka
- Israel
- www.mesicka.com

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ