Working Resources BadBlue 1.7.1 - Search Page Cross-Site Scripting
Author: Matthew Murphy type: webapps platform: cgi port: date_added: 2002-11-25 date_updated: 2012-10-17 verified: 1 codes: tags: aliases: screenshot_url: application_url: raw file: 22045.txt
source: https://www.securityfocus.com/bid/6253/info The ext.dll ISAPI does not sufficiently sanitize user-supplied input when processing search queries. This may allow an attacker to create a custom URL containing script code that, when viewed in a browser by a legitimate user, will result in the execution of the script code. ');alert(document.cookie);// ')" style="left:expression(eval('alert(document.cookie)'))">