cwbe coordinatez:
101
63540
1701996
4658010
4663087

ABSOLUT
KYBERIA
permissions
you: r,
system: public
net: yes

neurons

stats|by_visit|by_K
source
tiamat
K|my_K|given_K
last
commanders
polls

total descendants::
total children::1
show[ 2 | 3] flat


ako tak nad tym rozmyslam a citam si topic,

id 2244 (Xanthix )
1: Stored XSS v userinfo

toto nie je bug a vobec to medzi zranitelnosti (a topicu) nepatri. totiz kedysi sem siel injectnut lubovolny javascript kod, nielen do userinfa, ale do akejkolvek nody ("a povazovali to za feature"). samozrejme tu ten kod zostal, takze ludia, ktori si popridavali twitter-e, last.fm atd napriklad do profilu alebo zapisnikov, ho mozu nadalej pouzivat, nie vsak pridavat/menit. a XanthiX si vlozil XSS s alert()-om do userinfa -> nody (v tomto kontexte) ako kazda ina. v case vyhlasenia hack contest-u to vsak uz mozne nebolo, javascript tam zostal, ale nejde ho nijak zneuzit, pridat novy, alebo zmenit.

este dodam, https://kyberia.sk/id/4659122


  submission:: Re: namietka, alebo .. opravte ma, ak sa mylim :: NEW (1 children )   NEW DESCENDANT   (piece_of_IT)


There are currently 10254 K available in
2nd Guild's K-treasury.




get 1 🦆 for 5 🐘
get 1 🐘 for 1 🦆