BugTraq
CrossSite Scripting @ Snitz Forums 2000 Apr 17 2003 06:33PM
badwebmasters online de


Description:

The BadWord-(Script-)Filter can be tricked by adding the Tab-Char (0x09)

into the script command. This may lead to CrossSite-Scripting.

Exploit:

[img]jav asc ript:alert%28document.cookie%29[/img]

Vendor:

Has been contacted on 15. April.

Patch:

Available at http://int23.online.de/badwebmasters/txt/adv011.txt

greetZ bWM

-----------------------------------------------------

badWebMasters - online security vs. web underground

http://int23.online.de/badwebmasters

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus