lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20050415141130.31847.qmail@www.securityfocus.com> Date: 15 Apr 2005 14:11:30 -0000 From: Francisco Alisson <dominusvis@...ck21.com.br> To: bugtraq@...urityfocus.com Subject: myBloggie 2.1.1 ############################################ # # myBloggie 2.1.1 # Vendor: http://www.mywebland.com/ # ############################################ When the comments are posted there's no check for "<script>" tags allowing a script injection attack. Proof of Concept <script>alert("Hi world!");</script> ..-= Dominus_Vis =-.. [Infektion Group] Brazil