[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <4607C018.5010106@gmail.com>
Date: Mon, 26 Mar 2007 14:44:08 +0200
From: Florian Stinglmayr <fstinglmayr@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: Libero.it (italian ISP) XSS vulnerability
Rosario Valotta wrote:
> Libero.it, one of the most important italian ISP (www.libero.it) is
> affected from a XSS vulnerability.
> The vulnerability can be found in the "Community" section of Libero
> portal, and the affected functionality is "add nick" (
> http://digiland.libero.it/profilo.phtml?nick=).
> The implementation of this functionality allows the injection of
> malicious code in the URL, so that an attacker can steal username and
> password of the victim accessing his cookie.
>
Nice find!
--
Florian Stinglmayr
fstinglmayr@...il.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists