|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Knud Erik Højgaard (knud
cybercity.dk)Date: Tue Feb 05 2002 - 04:42:37 CST
To add to the late plethora of CSS bugs, ign.com has some too.
'Vendor' contacted about a week ago at various mailaddresses, no reply.
will show you some screenshots from 'knud fighter 4' (really virtua fighter 4 shots).. the &page_title=blabla doesn't filter <tags> so it's possible to steal cookies and whatnot.. I haven't tried in the members section, since i can't really access it without an account, but i assume it uses the same files since ps2.ign.com/pc.ign.com/pocket.ign.com all utilize mediaviewer.ign.com/mediaPage.jsp for their media (p)reviews.
random thought: is bugtraq really the correct place for css bugs? many vulnerable scripts are 'homemade' .. so it's not like there's much value in reporting 'site x has css bug in blah.php' ..
-Knud
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]