lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <93dbed490604161558k58255639s2710f44b53eb9dc7@mail.gmail.com>
Date: Sun Apr 16 23:58:34 2006
From: easy.mask at gmail.com (izi)
Subject: BetaBoard Cross Site Scripting vulnerability

//----- Advisory


Program          : BetaBoard
Homepage         : http://gonzo.uni-weimar.de/~scheffl2/betaboard/
Tested version   : 0.1
Found by         : Simon MOREL <philemon at thehackademy dot net>
This advisory    : Simon MOREL <philemon at thehackademy dot net>
Discovery date   : 2006/04/16



//----- Application description


BetaBoard is a small german forum in which thread list is displayed as
an indented tree.



//----- Description of vulnerability


Malicious JavaScript code can be insert in user's profile.



//----- Proof Of Concept


<script>alert('document.cookie')</script>



//----- Impact


Every user reading evil guy's profile can have his cookie stolen



//----- Credits


Simon MOREL <philemon at thehackademy dot net>
http://www.sysdream.com



//----- Greetings


Celelibi for his English ;>

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ