|
Title:=0D
[Kil13r-SA-20060609-3] DreamWiz Search Cross-Site Scripting Vulnerability=0D
=0D
Author:=0D
Kil13r - http://www.kil13r.info/=0D
=0D
Local / Remote:=0D
Remote=0D
=0D
Timeline:=0D
2006/06/09 - Discovery=0D
2006/06/09 - Vendor notification=0D
2006/06/09 - Release=0D
=0D
Affected version:=0D
=0D
Not affected version:=0D
=0D
Description:=0D
DreamWiz is internet portal site, but that has vulnerability.=0D
It can run arbitrary Javascript code by end user in search engine.=0D
=0D
If victim execute arbitrary Javascript code, attacker can steal victim's cookie.=0D
=0D
Proof of Concept code:=0D
None=0D
=0D
Proof of Concept example:=0D
None=0D
=0D
Proof of Concept screenshot:=0D
http://www.kil13r.info/sa/xss/dreamwizxss.jpg=0D