Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)

  File Including In PBLang

  [SA17333] phpESP Unspecified Cross-Site Scripting and SQL Injection

  [SA17353] gCards "limit" SQL Injection Vulnerability

  [Full-disclosure] Multiple vulnerabilities within RockLiffe MailSite Express WebMail

From:alex_(at)_aleksanet.com <alex_(at)_aleksanet.com>
Date:25.10.2005
Subject:Flat Nuke Cross Site Scripting

Web Site:

Vulnerable: FlatNuke <= 2.5.6

This script is possibly vulnerable to Cross Site Scripting (XSS) attacks

Malicious users may inject JavaScript, VBScript, ActiveX,  into a vulnerable application to fool a user in order to gather data from them.

Affects http://[target]TEST/flatnuke-2.5.6/forum/index.php


The script has been tested with these POST variables:

op=login&nome=<script>alert('LOL');</script>&
regpass=1&reregpass=1&anag=1&email=1&homep=http%3A%2F%
2F&prof=1&prov=1&ava=1&url_avatar=1&firma=1


op=login&from=home&nome=<script>alert('LOL');</s
cript>&logpassword=1

Best Regards
Alex

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru