Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Nikyt0x Argentina
    PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)



    [Nikkyt0x Advisory]
    #0000-0001

    [PHP Code Snippet Library Multiple Cross-Site Scripting (XSS) Vulnerabilities]


    Software: PHP Code Snippet Library
    Vendor: http://www.php-csl.com/
    Date: 24/08/2004
    Author: Nikyt0x [ nikyt0x@hotmail.com ]
    Site: http://nikyt0x.webcindario.com
    Advisory URL: http://nikyt0x.webcindario.com/0001.txt
    Vamos Argentina !

    [ Description ]

    It was designed to help PHP programmers store commonly
    used code in a central repository. Code can be stored
    in categories for easy managment.

    [ Vulnerability ]

    PHP Code Snippet Library not have html filters in:
    >cat_select
    >show


    [ Proof of concept ]

    http://localhost/[path]/index.php?cat_select=[XSS]
    http://localhost/[path]/index.php?cat_select=[XSS]&show=[XSS]

    Example:

    http://nikyt0x.webcindario.com/1.jpg




  2. #2
    at
    PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: PHP Code Snippet Library Multiple Cross-Site Scripting (XSS)

    Hi,

    This is a bugus bug report, I've tested this on both v0.8 and v0.9 and no problems.

    Please remove this bug as it gives a bad name to the project.

    It is possible to pass fake variables (as with most systems), but not executable code!! which is not a security issue.

    If I'm missing something, please email me with details info. But as far as I can see this is a bugus report.

    Stuart

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics