|
|||||||||||
|
Re: Execution of Javascript from PERL
From: Martin Eiszner <martin(at)websec.org>
Date: Thu Apr 17 2003 - 11:15:34 EDT hola,
On Thu, 17 Apr 2003 10:52:45 -0400
> The real problem is not getting the JavaScript in the page to execute, > it's getting it to execute in a meaningful context from the security-testing point of view its not necessary to execute any script .. because: IF input
"<script>thingstodo();</script>"
"<script>thingstodo();</script>" the application is definitively vulnerable !!! and it is a confuguration-issue to check for all "known" and "unknown" script-tags and -objects !!
nice day,
-- WebSec.org / Martin Eiszner Gurkgasse 49/Top14 1140 Vienna Austria / EUROPE mei@websec.org http://www.websec.org tel: 0043 699 121772 37Received on Thu Apr 17 11:46:45 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT |
||||||||||
|
|||||||||||