OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Full-disclosure] Exploitation Realm in Ajax Based Load Tab Modules

From: Aditya K Sood (zeroknockmetaeye.org)
Date: Thu May 03 2007 - 21:59:44 CDT


Hi all

This analysis compose of the active module checking derived from
AJAX based applications.This vulnerability or bad programming practise
 makes the web application vulnerable to XSS scripting and other
Javascript injections.

A very definitive analysis have been undertaken. You can look at the
desired issue at :

http://zeroknock.blogspot.com/2007/05/cutting-edge-research-analysis.html
http://zeroknock.metaeye.org/analysis/

Regards
Aditya K Sood
[MSG} Founder , Metaeye Security G

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/