发新话题
打印

[转载]WPkontakt Message Parsing Error

[转载]WPkontakt Message Parsing Error

信息来源:www.securiteam.com

Summary
WPkontakt is "a Polish instant messenger". Due to incorrect filtering don by WPkontakt, a remote attacker can inject arbitrary HTML/JavaScript into the content returned by the server.

Credit:
The information has been provided by Jaroslaw Sajko.

Details
Vulnerable Systems:
* WPKontakt version 3.0.1 and prior

Immune Systems:
* WPKontakt version 3.0.1p1 or newer

An error returned during the parsing an email addresses, allows a remote attack to inject HTML/JavaScript.

Example:
The following email address will trigger the error:
test@"style="background-image:url(javascript:alert(%22You%20are%20owned!%22>))".wp.pl
曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题