Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | WikiNi Persistent Cross Site Scripting Vulnerability |
|---|---|
| Date: | 29 May 2006 18:29:16 -0000 |
Hi, I've found a vulnerability more than 2 months ago, and notified the developers, but still no answer, so I'm posting here. http://zone14.free.fr/advisories/3/ Vendor: WikiNi Vulnerable: WikiNi 0.4.2 and below Persistent Cross Site Scripting A persistent XSS vulnerability is the most dangerous kind of XSS vulnerabilities, as the data submitted by the malicious user is stored permanently on the server. It could potentially hit a large number of other users with little need for social engineering. Just edit a page and insert: ""<script>alert('XSS Vulnerable');</script>"" Restrictions The attacker needs to have the rights to edit at least one page of the wiki, but most of the time it is the case. Moreover, WikiNi 0.4.2 is used on more than 100,000 pages according to Google. --Raphaël HUCK
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | New SMB and DCERPC features on Impacket released with doc, Gerardo Richarte |
|---|---|
| Next by Date: | [KAPDA::#46] - Nukedit Unauthorized Admin Add, farhadkey |
| Previous by Thread: | New SMB and DCERPC features on Impacket released with doc, Gerardo Richarte |
| Next by Thread: | [KAPDA::#46] - Nukedit Unauthorized Admin Add, farhadkey |
| Indexes: | [Date] [Thread] [Top] [All Lists] |