[Full-disclosure] MIMESweeper For Web 5.X Cross Site Scripting

Brian Eaton eaton.lists at gmail.com
Mon Jul 10 13:06:07 BST 2006


On 7/9/06, Erez Metula <erezmetula at 2bsecure.co.il> wrote:
> An example attack scenario could be that an attacker will redirect many
> users (by email, posting in the organization portal, etc.) to some blocked
> URL and an accompanying script that will steal their authentication cookies.

It sounds like the net impact of this vulnerability is that an
attacker can steal cookies for a site the user isn't allowed to visit
anyway.  In other words, there aren't going to be any interesting
cookies to steal.  Is there more to this attack scenario?

Regards,
Brian




Full-Disclosure is hosted and sponsored by Secunia.