Home page logo

bugtraq logo Bugtraq mailing list archives

Lame cross site scripting against www.ibm.com
From: Georgi Guninski <guninski () GUNINSKI COM>
Date: Mon, 30 Oct 2000 17:59:25 +0200

I know this is really lame issue but guess more sites suffer from it.
The search engine at http://www.ibm.com allows cross site scripting.
Try searching for:
+IBM -</TITLE><SCRIPT>alert(document.cookie)</SCRIPT>
or try the following url:

At least it seems not to allow SSI.

Vendor status:
IBM was notified at least 4 days ago.

Georgi Guninski

  By Date           By Thread  

Current thread:
  • Lame cross site scripting against www.ibm.com Georgi Guninski (Nov 03)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]