Web Hack List

Other nomination

Google Urchin password theft madness

Google Urchin 5's session.cgi login page takes an unfiltered parameter, giving reflected XSS on 5.6.00r2 through 5.7.03. pagvac shows it is worth more than an alert box: rewrite the form action, or exploit the browser's saved-password autocomplete, waiting 1.5s with setTimeout before shipping the filled username and password to an attacker image URL. Works on Firefox 2.0.0.7, not IE 7.

Record

Researcher
pagvac

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of pagvac, first published at the original source. Preserved copies are kept so the citation survives its host.