Re: Yet another XSS vulnerability in PHP NUKE

From: Muhammad Faisal Rauf Danka (mfrd@attitudex.com)
Date: 09/28/02


Date: Sat, 28 Sep 2002 05:20:57 -0700 (PDT)
From: Muhammad Faisal Rauf Danka <mfrd@attitudex.com>
To: bugtraq@securityfocus.com

This XSS issue with the search field has already been discovered and published by Mark Grimes.

see the link:
http://www.der-keiler.de/Mailing-Lists/securityfocus/bugtraq/2002-09/0289.html

Regards
--------
Muhammad Faisal Rauf Danka

Head of GemSEC / Chief Technology Officer
Gem Internet Services (Pvt) Ltd.
web: www.gem.net.pk
Key Id: 0x784B0202
Key Fingerprint: 6F8C EDCF 6C6E 06A5 48D7 6A20 C592 484B
784B 0202

_____________________________________________________________
---------------------------
[ATTITUDEX.COM]
http://www.attitudex.com/
---------------------------

_____________________________________________________________
Select your own custom email address for FREE! Get you@yourchoice.com w/No Ads, 6MB, POP & more! http://www.everyone.net/selectmail?campaign=tag



Relevant Pages

  • Re: dual booting with linux and w2k (newb)
    ... To newb: 1st try entering your subject line as the search field in ... Regards, Weird * IMPORTANT EMAIL INFO FOLLOWS * ...
    (alt.os.linux.suse)
  • Re: IE remember information that it should not
    ... Regards, ... MVP IE/OE ... Please reply to the newsgroup so that others may participate. ... > my userID once I enter it, or the search field for GOOGLE ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re[2]: [Full-Disclosure] Selfmade worms in the wild ;)
    ... m> and include some remote javascript of our choice, or the latest IE ADODB explot. ... m> this goes to show that XSS is still very much a security concern, ...
    (Full-Disclosure)
  • Re: Evolution of Cross-Site Scripting Attacks
    ... I have already detected on my logs a tool which scan for XSS, ... per second obviously imposible for "active human explotation", ... this incident to the incidents mailing list the 16th but for some reason ... Best Regards ...
    (Vuln-Dev)
  • Re: cant find patch 5086 on sgi.com
    ... enter '5086' in the search field at the bottom of the page. ... TakeNet GmbH Mobil: 0171/60 57 963 ...
    (comp.sys.sgi.admin)