From: philippe_mingo Date: Fri, 13 Sep 2002 08:26:30 +0000 (+0000) Subject: _MAIN_ Exploit: X-Git-Url: https://vcs.fsf.org/?a=commitdiff_plain;h=07dcee9fe75b37b4d622529550cf6e0820b7c056;p=squirrelmail.git _MAIN_ Exploit: The XSS hole I developed the most is in addressbook.php. I was able to inject and execute javascript code and after opening the addressbook page there was no indication that I had changed anything (after entering the HTML comment tags to get rid of some hanging code that my javascript had made text). The URL I crafted for the exploit is as follows: http://.net/webmail/src/addressbook.php?">