xss phpBugTracker 1.7.5 XSS / SQL Injection / Auth Bypass By packetstormsecurity.com Published On :: Sat, 16 May 2015 12:57:52 GMT phpBugTracker 1.7.5 suffers from cross site scripting, authorization bypass, and SQL injection vulnerabilities. Full Article
xss SanyBee Gallery 0.2.9 / 0.2.10 XSS / Add Admin By packetstormsecurity.com Published On :: Mon, 08 Jun 2015 17:22:22 GMT SanyBee Gallery versions 0.2.9 and 0.2.10 suffer from cross site scripting and add administrator vulnerabilities. Full Article
xss vbulletin-xssxsrf.txt By packetstormsecurity.com Published On :: Thu, 20 Nov 2008 22:44:51 GMT The Visitor Messages add-on for vBulletin version 3.7.3 suffers from cross site scripting and cross site request forgery vulnerabilities. This is a worm exploit that takes advantage of these issues. Full Article
xss Exploit Web 2.0, Real Life XSS-Worm By packetstormsecurity.com Published On :: Thu, 05 Feb 2009 22:08:04 GMT Whitepaper called Exploiting Web 2.0, Real Life XSS-Worm. Full Article
xss eBay Year-Long Patch Stall A Little XSSive By packetstormsecurity.com Published On :: Thu, 30 Apr 2015 13:57:01 GMT Full Article headline flaw ebay
xss Database Traffic Interception for Graybox Detection of Stored and Context-Sensitive XSS. (arXiv:2005.03322v1 [cs.CR]) By arxiv.org Published On :: XSS is a security vulnerability that permits injecting malicious code into the client side of a web application. In the simplest situations, XSS vulnerabilities arise when a web application includes the user input in the web output without due sanitization. Such simple XSS vulnerabilities can be detected fairly reliably with blackbox scanners, which inject malicious payload into sensitive parts of HTTP requests and look for the reflected values in the web output. Contemporary blackbox scanners are not effective against stored XSS vulnerabilities, where the malicious payload in an HTTP response originates from the database storage of the web application, rather than from the associated HTTP request. Similarly, many blackbox scanners do not systematically handle context-sensitive XSS vulnerabilities, where the user input is included in the web output after a transformation that prevents the scanner from recognizing the original value, but does not sanitize the value sufficiently. Among the combination of two basic data sources (stored vs reflected) and two basic vulnerability patterns (context sensitive vs not so), only one is therefore tested systematically by state-of-the-art blackbox scanners. Our work focuses on systematic coverage of the three remaining combinations. We present a graybox mechanism that extends a general purpose database to cooperate with our XSS scanner, reporting and injecting the test inputs at the boundary between the database and the web application. Furthermore, we design a mechanism for identifying the injected inputs in the web output even after encoding by the web application, and check whether the encoding sanitizes the injected inputs correctly in the respective browser context. We evaluate our approach on eight mature and technologically diverse web applications, discovering previously unknown and exploitable XSS flaws in each of those applications. Full Article
xss Contest Seeks The Most Diminutive XSS Worm By packetstormsecurity.com Published On :: Sat, 05 Jan 2008 08:06:56 GMT Full Article worm xss
xss Web Tools Create XSS Headaches By packetstormsecurity.com Published On :: Mon, 07 Jan 2008 15:48:51 GMT Full Article xss
xss Facebook Vulnerable To Critical XSS, Could Lead To Malware Attacks By packetstormsecurity.com Published On :: Fri, 23 May 2008 08:26:21 GMT Full Article malware facebook xss
xss Verisign, McAfee, And Symantec Sites Can Be Used For Phishing Due To XSS By packetstormsecurity.com Published On :: Mon, 09 Jun 2008 03:20:21 GMT Full Article verisign symantec phish mcafee xss
xss American Express Bitten By XSS Bugs Again By packetstormsecurity.com Published On :: Sat, 20 Dec 2008 08:30:00 GMT Full Article usa xss
xss XSS Flaws Poke Ridicule At Entertainment Industry By packetstormsecurity.com Published On :: Fri, 08 May 2009 09:06:46 GMT Full Article flaw xss
xss Adobe Plagued By 16-Month-Old XSS Bug By packetstormsecurity.com Published On :: Thu, 14 May 2009 08:22:15 GMT Full Article adobe xss
xss Mozilla Tackles XSS Vulnerabilities With New Technology By packetstormsecurity.com Published On :: Mon, 22 Jun 2009 16:29:11 GMT Full Article mozilla xss
xss MoD Website Outflanked By XSS Flaws By packetstormsecurity.com Published On :: Mon, 10 Aug 2009 02:30:05 GMT Full Article flaw xss
xss RubyOnRails XSS Vulnerability Claims Twitter, Basecamp And My Confidence By packetstormsecurity.com Published On :: Thu, 03 Sep 2009 14:57:22 GMT Full Article xss twitter
xss Reddit Swiftly Squishes XSS Worm By packetstormsecurity.com Published On :: Mon, 28 Sep 2009 04:42:36 GMT Full Article worm xss
xss XSS Vulnerabilities In 8 Million Flash Files By packetstormsecurity.com Published On :: Tue, 22 Dec 2009 09:16:16 GMT Full Article adobe xss
xss IE 8 XSS Filter Exposes Sites To XSS Attacks By packetstormsecurity.com Published On :: Mon, 19 Apr 2010 19:23:01 GMT Full Article microsoft xss
xss Serious XSS Flaw Haunts Microsoft SharePoint By packetstormsecurity.com Published On :: Thu, 29 Apr 2010 04:24:15 GMT Full Article microsoft flaw xss
xss Adobe Updates Flash Player To Fix XSS Flaw By packetstormsecurity.com Published On :: Tue, 07 Jun 2011 03:23:00 GMT Full Article headline adobe xss
xss Postcards From The Post-XSS World By packetstormsecurity.com Published On :: Wed, 21 Dec 2011 21:49:38 GMT Full Article headline flaw xss
xss XSS Flaw Discovered In Skype's Shop, User Accounts Targeted By packetstormsecurity.com Published On :: Fri, 24 Feb 2012 23:57:20 GMT Full Article headline flaw identity theft skype social xss
xss Abusing Password Managers With XSS By packetstormsecurity.com Published On :: Wed, 25 Apr 2012 19:00:23 GMT Full Article headline hacker flaw xss
xss Critical XSS Vulnerability Patched In WordPress Plugin GDPR Cookie Consent By packetstormsecurity.com Published On :: Thu, 13 Feb 2020 15:20:48 GMT Full Article headline flaw wordpress
xss Telerik ASP.NET AJAX RadEditor Control 2014.1.403.35 XSS By packetstormsecurity.com Published On :: Thu, 25 Sep 2014 15:20:36 GMT Telerik ASP.NET AJAX RadEditor Control versions 2014.1.403.35 and 2009.3.1208.20 suffer from a persistent cross site scripting vulnerability. Full Article
xss XSSer Penetration Testing Tool 1.8-1 By packetstormsecurity.com Published On :: Mon, 23 Sep 2019 20:04:03 GMT XSSer is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections against different applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. Full Article
xss XSSer Penetration Testing Tool 1.8-2 By packetstormsecurity.com Published On :: Mon, 18 Nov 2019 15:16:36 GMT XSSer is an open source penetration testing tool that automates the process of detecting and exploiting XSS injections against different applications. It contains several options to try to bypass certain filters, and various special techniques of code injection. Full Article
xss FIBARO System Home Center 5.021 Remote File Inclusion / XSS By packetstormsecurity.com Published On :: Mon, 23 Mar 2020 16:12:32 GMT FIBARO System Home Center version 5.021 suffers from cross site scripting and remote file inclusion vulnerabilities. Full Article
xss NICE Recording eXpress 6.x Root Backdoor / XSS / Bypass By packetstormsecurity.com Published On :: Fri, 30 May 2014 03:10:28 GMT NICE Recording eXpress versions 6.0.x, 6.1.x, 6.2.x, 6.3.x, and 6.5.x suffer from cross site scripting, root backdoor, unauthenticated access, fail authorization, insecure cookie handling, and remote SQL injection vulnerabilities. Full Article
xss ResourceSpace 6.4.5976 XSS / SQL Injection / Insecure Cookie Handling By packetstormsecurity.com Published On :: Thu, 11 Dec 2014 22:27:12 GMT ResourceSpace suffers from cross site scripting, html injection, insecure cookie handling, and remote SQL injection vulnerabilities. Versions 6.4.5976 and below are affected. Full Article
xss Prestashop 1.7.6.4 XSS / CSRF / Remote Code Execution By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 21:26:17 GMT Prestashop versions 1.7.6.4 and below suffer from code execution, cross site request forgery, and cross site scripting vulnerabilities. Full Article
xss Oce Colorwave 500 CSRF / XSS / Authentication Bypass By packetstormsecurity.com Published On :: Thu, 19 Mar 2020 22:03:23 GMT Oce Colorwave 500 printer suffers from authentication bypass, cross site request forgery, and cross site scripting vulnerabilities. Full Article
xss MicroStrategy Intelligence Server And Web 10.4 XSS / Disclosure / SSRF / Code Execution By packetstormsecurity.com Published On :: Thu, 02 Apr 2020 14:50:46 GMT MicroStrategy Intelligence Server and Web version 10.4 suffers from remote code execution, cross site scripting, server-side request forgery, and information disclosure vulnerabilities. Full Article
xss 900,000 WordPress Sites Attacked Via XSS Vulnerabilities By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:13:55 GMT Full Article headline hacker flaw wordpress
xss XSS Fuzzer By packetstormsecurity.com Published On :: Wed, 28 Nov 2018 17:42:43 GMT XSS Fuzzer is a simple application written in plain HTML/JavaScript/CSS which generates XSS payloads based on user-defined vectors using multiple placeholders which are replaced with fuzzing lists. It offers the possibility to just generate the payloads as plain-text or to execute them inside an iframe. Inside iframes, it is possible to send GET or POST requests from the browser to arbitrary URLs using generated payloads. Full Article
xss Transferable Remote 1.1 XSS / LFI / Command Injection By packetstormsecurity.com Published On :: Wed, 13 Feb 2013 03:00:01 GMT Transferable Remote version 1.1 for iPad and iPhone suffers from cross site scripting, remote command injection, and local file inclusion vulnerabilities. Full Article
xss Google Patches Awesome XSS Vulnerability In Gmail Dynamic Email Feature By packetstormsecurity.com Published On :: Mon, 18 Nov 2019 15:01:56 GMT Full Article headline email flaw google