Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
CSS before redirect Sep 08 2003 03:32PM
Stephen de Vries (stephen devries dcode net)

Hi all,

I'm looking at an application that seems to be vulnerable to CSS attack,
however, the browser keeps following the redirect before running the
script. The request:

GET /includes?"></a><script>alert('hello')</script> HTTP/1.1

Results in the following response:

HTTP/1.1 302 Object Moved
L...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus