exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

pLog.txt

pLog.txt
Posted Sep 9, 2004
Authored by Jason Thistlethwaite

pLog version 0.3.2 is susceptible to cross site scripting attacks in the register.php script.

tags | advisory, php, xss
SHA-256 | 5c082a2eaf11815b1b99b9760c6946d0863d78c0e25bf6e67ac3bd581767e018

pLog.txt

Change Mirror Download
From: Iadnah  iadnah@lesrahpem.homelinux.org
Tue, 31 Aug 2004 17:24:14 -0400


I believe I have discovered a vulnerability in the open source blog
software known as pLog. Register.php doesn't seem to check for script
tags in the username or blog name fields in the account sign up form.

This allows injection of potentially malicious code into the page. Since
the names of blogs are displayed on the summary.php page, anyone who
sees that page would be subject to execution of said code.

I have contact the developers about this. They have verified the bug and
are working on a fix.

Jason Thistlethwaite


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    69 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close