Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: ASPKnowledgebase vulnerable to XSS injection.

ASPKnowledgebase vulnerable to XSS injection.

From: <preben_at_watchcom.no>
Date: 9 Nov 2005 12:01:20 -0000
('binary' encoding is not supported, stored as-is) ASPKnowledgebase, by www.asp-programmers.com is vulnerable to XSS in some of it's input fields. If you compromise it's logon, to gain administrative privileges as my previous advisory describes - you can inject the admin form-fields with XSS.
This will result in automatic execution of script when a user visits that page.

This is highly dangerous as you can script what ever you like. Often these types of attacks are used for cookie thefts and so on.

Please credit to: Preben Nyløkken
Received on Nov 09 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]