TUCoPS :: Web :: Apps :: b06-3387.htm

Massting Cross-Site Scripting Vulnerability
Massting Cross-Site Scripting Vulnerability
Massting Cross-Site Scripting Vulnerability



Title:=0D
[Kil13r-SA-20060701-3] Massting Cross-Site Scripting Vulnerability=0D
=0D
Author:=0D
Kil13r - http://www.kil13r.info/=0D 
=0D
Local / Remote:=0D
Remote=0D
=0D
Timeline:=0D
2006/06/30 - Discovery=0D
2006/06/30 - Vendor notification=0D
2006/06/30 - Vendor response=0D
2006/06/30 - Vendor fix=0D
2006/07/01 - Release=0D
=0D
Affected version:=0D
=0D
Not affected version:=0D
=0D
Description:=0D
Massting is AJAX chat service site, but that has vulnerability.=0D
It can run arbitrary Javascript code by end user in message input form.=0D
=0D
Proof of Concept code:=0D
=0D
=0D
Proof of Concept example:=0D
None=0D
=0D
Proof of Concept screenshot:=0D
None=0D
=0D
-=0D
The Bird of Hermes is my name,=0D
Eating my wings to make me tame.=0D

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH