about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Lycos HTMLGear guestGear CSS HTML Injection Vulnerability


Title Lycos HTMLGear guestGear CSS HTML Injection Vulnerability
Published 2002-09-17-12:00AM
Updated 2002-09-17-10:00PM
Class Input Validation Error
CVE   CAN-2002-1493 CVE-2002-1493
Remote  Yes
Local  No
Credit  Discovery of this issue is credited to "Matthew Murphy" <mattmurphy@kc.rr.com>.
Vulnerable  Lycos htmlGEAR guestGEAR
Not Vulnerable  
Code   By specifying an e-mail address/web page URL like the following:

" STYLE="expression([javascript])

The JavaScript block will execute. Some less-paranoid versions of the
guestbook also allow a typical IMG attack:

<IMG SRC="javascript:[javascript]">
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 21:20:08 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
vedie PHP Advanc name of me www.sexywe ms04-22 sex vide news for c CMS+is+F.. Dede sex grayvee.co world live 2.4.12 loc comgirl16. news for c polymer ex go-private lesbean se mod_thrott vdj d-link +www.trish guest book www.Waptri nansisex www.17paib Www.Xxxtoo 200 /compo Microsoft super k.o sexwomn 2.6.8-12 200 /compo news for C lo865l linux root t187t WWW.nayant Ajithnudew 18ans Crack Data 200 /compo www.fuckth www.bigboo news for c Downloadvi free viedo t488t ADULT www.Sexwal news for c