[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <201010190924.o9J9ONPR006992@bari.maths.usyd.edu.au>
Date: Tue, 19 Oct 2010 20:24:23 +1100
From: paul.szabo@...ney.edu.au
To: an@...com, bugtraq@...urityfocus.com
Subject: Re: RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo
Dear An,
> Referrer: <script>alert(1)</script>
Yes, but... seems not all echo's get a Referer passed to them.
Cheers, Paul
Paul Szabo psz@...hs.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics University of Sydney Australia
Powered by blists - more mailing lists