Bugtraq mailing list archives
Tikiwiki 1.9.7 HTML/embed object injection
From: morin.josh () gmail com
Date: 24 Aug 2007 06:57:59 -0000
Tikiwiki Version: 1.9.7 Example Address http://example.com/tiki-remind_password.php Overview: The following codes can be added to the HTML password page by placing the HTML codes in the user name input box and hitting the "send me my password" button. Examples: 1.<br><br><b><u>XSS</u></b> 2.<EMBED SRC="http://site.com/xss.swf" 3.<html><fontcolor="Red"><b>Pwned</b></font></html>
Current thread:
- Tikiwiki 1.9.7 HTML/embed object injection morin . josh (Aug 24)
