|
From: spiffomatic 64 <spiffomatic64@hotmail.com>
Date: Tue May 18 2004 - 11:40:28 EDT
Vendor : WEBCT
Description: WebCT is the world's leading provider of e-learning systems for
institutions.
WebCT's vision is to deliver innovative e-learning solutions to help
improve educational outcomes for students around the world.
WebCT is a trusted industry leader in providing e-learning systems for
institutions. Thousands of institutions in more than 70 countries worldwide
the boundaries of teaching and learning with WebCT.
Cross site scripting: The filtering script for the discussion board doesnt
img, or object. All of which can take advantage of xss and because of the
setup this lead to full access to their email, and account information.
Solution: The easiest way would be to just disallow iframe,img,and object
at all.
Credits: Credits goto http://hackthissite.org. It provided a nice, open,
for me to try new things and learn from those who know. A place where you
reprimanded even if u deface a page or two. A place where I started with no
in less than a year found new vulnerabilities of my own. Thank you
Lab rats: The Nick's, Shrinidhi, Charbel and most importantly to Halley, you
strength and courage to do all that I do, without you I am nothing. Thank
Exploit: This is exploited using iframe,img, or object tags to redirect you
site.
Spiffomatic64
_________________________________________________________________
_______________________________________________
This archive was generated by hypermail 2.1.8 : Tue May 18 2004 - 14:06:22 EDT |
Custom Search
|