#----------------------------------------------------------

#Aria-Security.net Advisory

#Discovered  by: O.U.T.L.A.W

#< www.Aria-security.net>

#Gr33t to: A.u.r.a  & [EMAIL PROTECTED] & Smok3r

#-----------------------------------------------------------

» Software: Thyme 1.3 

» Link: http://www.extrosoft.com/products/thyme/demo/index.php

» Attack method: Cross Site Scripting

» advisory:http://www.aria-security.net/portals/thyme


» Summary:

Thyme is a calendar system


»Description

A Remote User Can Steal the sessioncookie by searing 
<script>alert(document.cookie)</script><!-- in search page 





» Solution

contact me: [EMAIL PROTECTED]


Reply via email to