Browse by Tags

Debug Message XSS Vulnerabilities
I was excited this afternoon when I thought that I'd stumbled upon a universal XSS vulnerability in verbose ColdFusion error messages. While testing a site, I had noted that a verbose debug error message (see below) echoed back many of the request Read More...
Posted 23 March 07 12:35 by Erik | 3 Comments   
Filed under ,
How Prevalent Are XSS Vulnerabilities?
How Prevalent Are Cross Site Scripting (XSS) Vulnerabilities? Based on a recent experiment, I wasn't surprised to see that they're everywhere and finding dozens at a time doesn't present much of a challenge. Back in September, 2006 I sought Read More...
Posted 31 January 07 01:27 by Erik | 4 Comments   
Filed under ,