lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 3 Nov 2009 17:20:06 -0700 From: Bugs NotHugs <bugsnothugs@...il.com> To: bugtraq <bugtraq@...urityfocus.com>, fd <full-disclosure@...ts.grok.org.uk> Subject: e-Courier Tracking Site Multiple Script UserGUID Parameter XSS Vendor: e-Courier (http://www.ecouriersoftware.com/) Product: CMS Tracking Site Issue: Cross-Site Scripting. Description: Nearly all pages include the URI Parameter UserGUID, which is not sanitized before being included in the response. Example: https://demo.e-courier.com/demo/home/index.asp?UserGUID="><script>alert(document.cookie)</script> -- BugsNotHugs Shared Vulnerability Disclosure Account _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists