Re: [Full-disclosure] MyNews 1.6.X HTML/JS Injection Vulnerability

2008-02-07 Thread Fredrick Diggle
SkyOut is a Fredrick Diggle Sec contributer... We suggest you think very carefully before insulting him further. Consider yourself on the list reepex. On Feb 6, 2008 9:57 PM, reepex <[EMAIL PROTECTED]> wrote: > your 'disclosure' is lame and so is your site. Could you please never email > here agai

Re: [Full-disclosure] MyNews 1.6.X HTML/JS Injection Vulnerability

2008-02-06 Thread reepex
your 'disclosure' is lame and so is your site. Could you please never email here again On Feb 6, 2008 1:06 PM, SkyOut <[EMAIL PROTECTED]> wrote: > I know its basic, but I am a supporter of FD and therefore > planetluc.com has to be > blamed now! I checked their script MyNews in version 1.6.4 toda

[Full-disclosure] MyNews 1.6.X HTML/JS Injection Vulnerability

2008-02-06 Thread SkyOut
I know its basic, but I am a supporter of FD and therefore planetluc.com has to be blamed now! I checked their script MyNews in version 1.6.4 today and then some other versions, all are vulnerable to HTML and JS injection. --- ADVISORY --- || WWW.SMASH-THE-STACK.N