Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
BugTraq
Back to list
|
Post reply
Airkiosk/formlib application is XSS vuln
Oct 30 2007 12:40AM
skienlab gmail com
(1 replies)
In the last week I've found a XSS vuln into the Sutra's Airkiosk
application for the realtime distribution of flights/booking and
check-in interface (www.airkiosk.com).
The XSS is possible because they are using a VULN/OLD formlib.pl in
their application that permits to execute any JavaScript you like:
&HtmlError("formlib.parse", "bjelli", "Error parsing $_, aborting.\n");
if you get the error 'f you need help, call bjelli.'.
I suppose it can be related to this flying companies (I've only tryed it
on Blu-express, and Jet2.com):
Aero, Jet2.com, Air southwest, manx2, airsea, republicaairways,
blu-express, highland airways, blueisland, tobagoexpress, evolavia,
zambian, menajet.com, snowflake, airwales and other that is can be easy
found by searching on google.
The maintainer (and the flying company blu-express) has been contacted
twice via mail in the last two weeks but choose not to respond at all.
Regards
Skien
[ reply ]
Re: Airkiosk/formlib application is XSS vuln
Nov 01 2007 04:39PM
Raymond Pete (pete airkiosk com)
(1 replies)
Re: Airkiosk/formlib application is XSS vuln
Nov 01 2007 05:37PM
skien (skienlab gmail com)
Privacy Statement
Copyright 2009, SecurityFocus
application for the realtime distribution of flights/booking and
check-in interface (www.airkiosk.com).
The XSS is possible because they are using a VULN/OLD formlib.pl in
their application that permits to execute any JavaScript you like:
&HtmlError("formlib.parse", "bjelli", "Error parsing $_, aborting.\n");
if you get the error 'f you need help, call bjelli.'.
I suppose it can be related to this flying companies (I've only tryed it
on Blu-express, and Jet2.com):
Aero, Jet2.com, Air southwest, manx2, airsea, republicaairways,
blu-express, highland airways, blueisland, tobagoexpress, evolavia,
zambian, menajet.com, snowflake, airwales and other that is can be easy
found by searching on google.
The maintainer (and the flying company blu-express) has been contacted
twice via mail in the last two weeks but choose not to respond at all.
Regards
Skien
[ reply ]