Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13241
HistoryJun 18, 2006 - 12:00 a.m.

VampireFreaks journal XSS

2006-06-1800:00:00
vulners.com
7

yes the journal is exploitable aswell

there seem to be no filters on the journal title so you can simply put: "><script>alert('XSS')</script>

also the other places where you can update your journal etc. don't filter anything

proof:
http://vampirefreaks.com/journal.php?u=NanoyMaster