lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20061130184548.18573.qmail@securityfocus.com> Date: 30 Nov 2006 18:45:48 -0000 From: mr_kaliman@....com To: bugtraq@...urityfocus.com Subject: @lex Guestbook 4.0.1 : Full Path Disclosure & XSS @lex Guestbook 4.0.1 -------------------- Vendor site: http://www.alexphpteam.com/ Product: @lex Guestbook 4.0.1 Vulnerability: Full Path Disclosure & XSS Credits: Mr_KaLiMaN Reported to Vendor: 24.11.06 Public disclosure: 30.11.06 Description: ------------ Full Path Disclosure: http://[victim]/[guestbook_path]/index.php?skin=[non-existent_skin] XSS: http://[victim]/[guestbook_path]/index.php?skin=[XSS]