CrossSite Scripting @ Snitz Forums 2000

From: badwebmastersat_private
Date: Thu Apr 17 2003 - 11:33:38 PDT

  • Next message: Muhammad Faisal Rauf Danka: "Fwd: CERT Advisory CA-2003-13 Multiple Vulnerabilities in Snort Preprocessors"

    
     ('binary' encoding is not supported, stored as-is)
    Description:
    
    The BadWord-(Script-)Filter can be tricked by adding the Tab-Char (0x09) 
    into the script command. This may lead to CrossSite-Scripting.
    
    
    Exploit:
    
    [img]jav	asc	ript:alert%28document.cookie%29[/img]
    
    
    Vendor:
    
    Has been contacted on 15. April.
    
    
    Patch:
    
    Available at http://int23.online.de/badwebmasters/txt/adv011.txt
    
    
    
    greetZ bWM
    
    
      -----------------------------------------------------
       badWebMasters - online security vs. web underground
             http://int23.online.de/badwebmasters
    



    This archive was generated by hypermail 2b30 : Thu Apr 17 2003 - 14:39:50 PDT