full-disclosure-uk August 2008 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: Re: [Full-disclosure] Multiple XSS Vulnerabi

Re: [Full-disclosure] Multiple XSS Vulnerabilities in Self Generate CMS (K?rast)

From: <devildeath1988_at_nospam>
Date: Sun Aug 24 2008 - 23:46:12 GMT
To: full-disclosure@lists.grok.org.uk

I Have found one more vulnerable value which is not cleaned before it would be displayed. When you search, there would be a POST value 'search=injection'. It's like the page value.

See here:


Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/