Saturday, December 11, 2010

The CMU Pronouncing Dictionary vulnerable to XSS

# Exploit Title: The CMU Pronouncing Dictionary vulnerable to XSS
# Google Dork: none
# Date: 11 December 2010
# Author: p0pc0rn
# Software Link: https://cmusphinx.svn.sourceforge.net/svnroot/cmusphinx/trunk/cmudict/



XSS
====
http://site/something/cmudict?in=[xss]


Screenshot
===========


http://img72.imageshack.us/img72/9166/cmudict.png

Status
=======
Reported on 11th December 2010
and Fixed by the developer on 12th December

Thanks

p0pc0rn
Share:

0 comments: