For example
Add %22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%3E
to the URL:
http://codestriker.sourceforge.net/cgi-bin/codestriker.pl?topic=7063366&action=view
It lets us run arbitrary javascript code. I think there will be perl module which can validate html form fields and strip malicious code from it if there is any.
Thanks to Dmitry Savintsev, my colleague who pointed it out.
Screen shot attached
Nobody/Anonymous
None
None
Public
|
Date: 2008-01-18 13:13:17 PST
|
| Filename | Description | Download |
|---|---|---|
| codestriker_xss.png | Screen shot of XSS in action | Download |