[Full-disclosure] MIMESweeper For Web 5.X Cross Site Scripting
Brian Eaton
eaton.lists at gmail.com
Mon Jul 10 13:06:07 BST 2006
On 7/9/06, Erez Metula <erezmetula at 2bsecure.co.il> wrote:
> An example attack scenario could be that an attacker will redirect many
> users (by email, posting in the organization portal, etc.) to some blocked
> URL and an accompanying script that will steal their authentication cookies.
It sounds like the net impact of this vulnerability is that an
attacker can steal cookies for a site the user isn't allowed to visit
anyway. In other words, there aren't going to be any interesting
cookies to steal. Is there more to this attack scenario?
Regards,
Brian
Full-Disclosure is hosted and sponsored by Secunia.