opensubscriber
   Find in this group all groups
 
Unknown more information…

h : htdig-dev@lists.sourceforge.net 25 September 2007 • 7:10PM -0400

[htdig-dev] XSS error in sytnax.html
by Michael Skibbe

REPLY TO AUTHOR
 
REPLY TO GROUP




Hi,

there is a XSS error in syntax.html of htdig.

you can reproduce this like this:
http://foo.bar/cgi-bin/htsearch?config=&restrict=&exclude=&method=and&format=builtin-long&sort=<script>alert("foo")</script>&words=foo

$(SYNTAXERROR) must be quoted by htdig before filling it in.

greetings
Michael
--
Michael Skibbe <mskibbe@suse...>
Core Services
SUSE Linux Products GmbH                      GF: Markus Rex
Nuernberg, Germany                            HRB 16746 (AG Nuernberg)

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
ht://Dig Developer mailing list:
htdig-dev@list...
List information (subscribe/unsubscribe, etc.)
https://lists.sourceforge.net/lists/listinfo/htdig-dev

Bookmark with:

Delicious   Digg   reddit   Facebook   StumbleUpon

opensubscriber is not affiliated with the authors of this message nor responsible for its content.