-
# Autopsy Forensic Browser Cross Site Scripting
--------------------------------------------------------------------------
Autor: Daniel Medianero garcĂa ( dmedianero @ sia.es )
Vendor: Autopsy Forensic Browser - http://www.sleuthkit.org/autopsy/
Impact: Cross Site Scripting
URL: http://www.meleagro.es.kz
Affected applications:
----------------------
- Autopsy Forensic Browser...
2008-08-31 08:53:57 UTC in The Autopsy Forensic Browser
-
File Added: XSS_agora_002.JPG.
2008-01-03 10:07:08 UTC in w-agora
-
Hi,
I am Daniel Medianero( dmedianero@gmail.com ) from http://m313.es.kz
I have discovered two variables that are vulnerable to XSS( A1 - OWASP).
In the page admin_user.php the variables userid and pattern.
Introducing unexpectes values is able to inyect html code.
I send us two evidences:
1) In the first I inyected a script with shows the cookie of visitor.
2) In the second I...
2008-01-03 10:06:50 UTC in w-agora