[NEWS] Cross Site Scripting in the Translation and Infoplease Services of lycos.com
From: support@securiteam.comDate: 03/15/02
- Previous message: support@securiteam.com: "[UNIX] Ecartis / Listar multiple vulnerabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Fri, 15 Mar 2002 16:14:03 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Cross Site Scripting in the Translation and Infoplease Services of
lycos.com
------------------------------------------------------------------------
SUMMARY
It is possible to perform a cross site scripting (CSS) attack on the
translation and infoplease services of lycos.com.
DETAILS
The translation and infoplease services of lycos.com do not check for
hostile input and do not filter characters such as "<" or ">", so it is
possible to steal cookies.
Impact:
It is possible to steal cookies by providing the victim with a custom
lycos.com URL.
Exploit:
The only thing you have to do is enter some HTML code in the textbox or
just click on the following links:
translation.lycos.com:
alert(document.cookie)&lp=en_de&partner=demo-Lycos2-en">http://translation.lycos.com/?urltext=