EHS Blog
Home  
 

 
Categories


Web Hosting
Website Design
PHP
Perl
JSP
   

 
Archives

No Records !!!
   
 

 
More CSRF Redirectors
at 2007-08-12 15:10:20


Today I learned about another CSRF redirector by another group of people in web application security called GNUCITIZEN.


Similar to the previous CSRF redirector it contains the same XSS vulnerability through the javascript URI scheme.


Example:

http://www.gnucitizen.org/util/csrf?..._url=javascript:alert(/.../);


Update: The bug is fixed for now...



Blog Source - http://blog.php-security.org/feeds/index.rss
 


Last 10 Posts
   
  - Shuffling methods

  - dirname(__FILE__)

  - static __call

  - Making $$$ with PHP

  - Improving executor

  - Graceful recovery

  - Kill resources

  - We are doomed!

  - Namespaces - can we keep it simple?

  - Linux World

   


Check Out Amazon