|
Bugtraq
mailing list archives
myBloggie 2.1.1
From: Francisco Alisson <dominusvis () click21 com br>
Date: 15 Apr 2005 14:11:30 -0000
############################################
#
# myBloggie 2.1.1
# Vendor: http://www.mywebland.com/
#
############################################
When the comments are posted there's no check for "<script>" tags allowing a script injection attack.
Proof of Concept
<script>alert("Hi world!");</script>
..-= Dominus_Vis =-..
[Infektion Group]
Brazil
By Date
By Thread
Current thread:
- myBloggie 2.1.1 Francisco Alisson (Apr 15)
|