alsoisp
Forum Replies Created
-
Forum: Plugins
In reply to: [SpiderFAQ] css vulnerabilityI can’t send you the query here, please give me a mail to sent it.
Forum: Plugins
In reply to: [SpiderFAQ] css vulnerabilityEnter the following XSS payload as search query:
// . “–!>
//
I hope we see the query here in your Ticketsystem. In the post before, the query was interpretet.
Forum: Plugins
In reply to: [SpiderFAQ] css vulnerabilityHello,
here is the original message:
Dear Sir/Madam,
I would like to report a XSS vulnerability that I have found on the alsoisp.de website. The
discovered vulnerability occurs because of incorrectly validated user input in the search function.
The vulnerability has been tested with the latest version of Firefox on Linux (Firefox 58.0.2 64-bit).
Reproduction
Go to: http://alsoisp.de/buchhaltung/
Enter the following XSS payload as search query:
“–!>
The JavaScript dialog will pop-up:
When we look at the source code we can see the JavaScript that was executed by the browser:
Mitigation
My recommendation would be to filter the search input for special characters used in HTML and
JavaScript.
I hope that my findings and report can contribute to a better and more secure website of the alsoisp
organization.Hello Tobias,
thx for the fast help.
Regards
Stephandone 😉
Regards
StephanHello 🙂
I can do that….
I do not want to publish. How can I send you this.Stephan
Hallo Tobias.
Kann ich gerne machen aber….. möchte ich nicht veröffentlichen. Wie kann ich dir diese zukommen lassen.
Gruss
Stephan