[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Re: Arin.net XSS
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Re: Arin.net XSS
- From: "Dave Korn" <davek_throwaway@xxxxxxxxxxx>
- Date: Mon, 6 Mar 2006 14:18:36 -0000
Michael Holstein wrote:
>> Here's a link that will probably work under both browsers
>>
>> http://ws.arin.net/whois/?queryinput=%3Cscript%3Ealert('666')%3C/script%3E
>
> (Firefox 1.5.0.1 on Linux)
>
> No match found for <script>alert('666')</script>.
>
Works on 1.0.x, I got the popup!
cheers,
DaveK
--
Can't think of a witty .sigline today....
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/