|
Re: More Cross site Scripting in PHPNuke: msg#00369security.bugtraq
Subject: More Cross site Scripting in PHPNuke u can do other thing but it isn't exploitable :( a local hack: In the search input, you write: "><h1><marquee>Hacked by Shaolinn</marquee></h1><" The php file request the input, and finally write the html page something like this: <input type="text" name="search" value="$search_input_requested"> then when i write ">anyhtmlthing<" i am injecting html. really this have not any utility :) but, you can learn how injection works. -- Shaolinn -- _________________________________________________________________ Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp. |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Trendmicro - Interscan - List of BCC: is revealed when stripping attachments and notifying destination addresses: 00369, Rich Lafferty |
|---|---|
| Next by Date: | [SECURITY] [DSA-128-1] sudo buffer overflow: 00369, Wichert Akkerman |
| Previous by Thread: | More Cross site Scripting in PHPNukei: 00369, Replugge [ROD] |
| Next by Thread: | De-anonymizer: 00369, Berend-Jan Wever |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |