Home page logo

bugtraq logo Bugtraq mailing list archives

TorrentFlux User-Agent XSS Vulnerability
From: sec () srasg stevenroddis com au
Date: 6 Oct 2006 01:30:33 -0000

Name: TorrentFlux User-Agent XSS Vulnerability
Published: 2006-10-06
Critical Level: Moderate
Type: Cross-Site Scripting
Where: Remote
Status: 0-Day
Software: Torrentflux 2.1
Discoverer: Steven Roddis (http://www.stevenroddis.com.au)
I gave the authors of this product a week (more than usual) just to contact me, they have failed to do so; so I am 
releasing this vulnerability publicly!
Line: 325
$ip_info = $ip_resolved."
Useragent is not esacped.
Edit source code:
Line: 325:
$ip_info = htmlentities($ip_resolved)."

  By Date           By Thread  

Current thread:
  • TorrentFlux User-Agent XSS Vulnerability sec (Oct 06)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]