antena1.ro XSS hack

antena1.ro XSS hack

06/04/08 | by zveriu | Categories: AskAmit, Hack, XSS

I use to watch Badea’s show “In gura presei” kindly provided as a recorded streaming on antena1.ro

While listening to the stream, I could not resist checking the site design, functionality and of course it’s security.

And voila - it seems that streaming archive section of antena1.ro is XSS-reflection vulnerable.

antena1.ro XSS hack
antena1.ro XSS hack

Code for PoC XSS reflection:

Code:

DISCLAIMER: this post is intended purely for security research and educative purposes as well as intended to urge the vendor to fix the problems posing threats to its customers. Any use of this information is sole responsibility of the reader and the author is not to be held liable for any miss-use of the above informative technical details.

Comments, Pingbacks:

No Comments/Pingbacks for this post yet...

This post has 1 feedback awaiting moderation...

Leave a comment:

Your email address will not be displayed on this site.
Your URL will be displayed.

Allowed XHTML tags: <p, ul, ol, li, dl, dt, dd, address, blockquote, ins, del, span, bdo, br, em, strong, dfn, code, samp, kdb, var, cite, abbr, acronym, q, sub, sup, tt, i, b, big, small>
(Line breaks become <br />)
(Set cookies for name, email and url)
(Allow users to contact you through a message form (your email will NOT be displayed.))
This is a captcha-picture. It is used to prevent mass-access by robots.
Please enter the characters from the image above. (case insensitive)

Projects

cetatenie.ro

Cognitive and Scientific Brainology

A deep dive into brain's curiosities

February 2012
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29      

Categories

Misc

XML Feeds

What is RSS?

powered by b2evolution free blog software