hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Help - Search - Member List - Calendar
Full Version: Type Xxs
GovernmentSecurity.org > The Archives > Exploit Articles
qcred11
Aug 7 2004, 10:06 PM
QUOTE


Vendor : typepad.com
URL : http://typepad.com
Risk : Cross site scripting


Description: TypePad is a powerful, hosted weblogging service that gives
users the richest set of features to immediately share and publish
information -- like travel logs, journals and digital scrapbooks -- on
the Web. TypePad lets people communicate, publicly or privately, with
the audience of their choosing.




Cross site scripting: The filtering script for the name form doesnt
filter " if preceeded by a ?. The cross site scripting works because the
<a href=" tag can be closed by a target url with " which then permits
the user to use such oneventhandles as onmouseover.


Solution: The easiest way would be to just replace all characters with
their &#xx; equivilant.


Credits: Credits goto my loving fiance, you push me todo things i never
thought possible.


Exploit: This is exploited by passing a url with malicious javascript to
the name variable.


Spiffomatic64



Source: http://seclists.org/lists/bugtraq/2004/Aug/0111.html
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.