[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <024C0137-1489-405D-B364-4E3343666F78@gmail.com>
Date: Sun, 4 Oct 2009 12:22:59 -0700
From: Andrew Farmer <andfarm@...il.com>
To: Jaloh Smith <jal0h@...mail.com>
Cc: Full Disclosure <full-disclosure@...ts.grok.org.uk>
Subject: Re: Geeklog <= v1.6.0sr2 - Remote File Upload
On 4 Oct 2009, at 08:47, Jaloh Smith wrote:
> The
> easy one is when the forum allows anonymous posts and is configured
> for
> text posts. The anonymous user name is never filtered, so you can put
> anything there, including a reference to the javascript uploaded as
> the
> user profile image..
>
> <script src="../images/userphotos/username.jpg"></script>
That's actually a much worse exploit than the file upload. There's no
reason the script you load has to be stored locally -- it works just
as well if you pull it from another domain.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists