TUCoPS :: Windows :: tb10146.htm

Windows Live Spaces logged user NetworkSetup.aspx cross site scripting
Windows Live Spaces logged user NetworkSetup.aspx cross site scripting
Windows Live Spaces logged user NetworkSetup.aspx cross site scripting



Windows Live Spaces has a XSS vulnerability in NetworkSetup.aspx page.

This vuln affects every windows live space and it works only on logged users.

With this vuln you can grab cookies and so gain the access to the blog's admin panel, where you can edit user's options and data, MSN Messenger nickname, personal image and other informations too.

Here a PoC:
http://bug.spaces.live.com/NetworkSetup.aspx?dp=1&cfs=%22%3E%3Cscript%3Ealert(%22XSS%22);%3C/script%3E 

Credits: Paolo Di Febbo

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH