about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , InstantForum.NET Multiple Cross Site Scripting Vulnerabilities


Title InstantForum.NET Multiple Cross Site Scripting Vulnerabilities
Published 2007-01-15-12:00AM
Updated 2007-01-15-09:10PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Doz is credited with the discovery of these vulnerabilities.
Vulnerable  InstantASP InstantASP 4.1
Not Vulnerable  
Code   To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.

The following proof-of-concept URIs are available:

http://www.example.com/Forums-Path/Logon.aspx?SessionID=[xss]
http://www.example.com/Forums-Path/Members1.aspx?Username=[xss]
http://www.example.com/Forums-Path/Members1.aspx?Update=[xss]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 15:41:58 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.szlwh. invasion Seaxy vide bot net Trisha pic www.cams.c www.huayuh amaricanse v.i.c. naguar Www.69.com M.../../et pop3 red h Www.69.com nakedaishw www.baobao www.besiba /search/ex www.chinap my free pa WOMAN AND Login to C Deasibaba. Modernbill Login to C Login to C Bf vidos 1duobao.ji 200+%252Fc www.net-ri sex es H....txt?\ n...Fnia.t www.net-ri ProFTPD 1. american s www.ep05.c php-nuke 2 PHP 4.4.4 Mobile no maxcpm.inf maxcpm.inf Indian hot sexywoman nude celeb ze .../ski xingyuan.z www.bebo.l priyamanis GET /class