Re: GamePlay.co.uk XSS

2006-06-17 Thread Patrick Morris
On Sat, 10 Jun 2006, [EMAIL PROTECTED] wrote: > The current password is not necessary for a successful password change for > members of gameplay.co.uk which makes changing passwords through scripts as > easy as tying your shoe lace. > (https://shop.gameplay.co.uk/gameplay/changepassword.asp) >

GamePlay.co.uk XSS

2006-06-13 Thread charlie
Homepage: www.gameplay.co.uk Example: http://shop.gameplay.co.uk/webstore/advanced_search.asp?Keyword=&terms=!&badterm=alert(document.cookie) Also... The current password is not necessary for a successful password change for members of gameplay.co.uk which makes changing passwords through s