<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
<channel>
<title>Ivan Markovic - Security Net - Site exposed</title>
<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195</link>
<description>RSS feed - Site Exposed</description>
<language>sr</language>
<ttl>15</ttl>

<item>
	<title>ISP | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=283</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=283</guid>
	<description>&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip sajta:&lt;/span&gt; ISP&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Detalji:&lt;/span&gt; POST forma za proveru slobodnih domena prihvata specijalne karaktere.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Savet:&lt;/span&gt; Pretvorite specijalne karaktere u odgovarajuce html entitete.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Pronasao:&lt;/span&gt; &lt;a href=&quot;http://www.security-net.biz/&quot; target=&quot;_blank&quot;&gt;Ivan Markovic&lt;/a&gt;</description>
	<pubDate>Wed, 18 Feb 2009 10:47:03 +0100</pubDate>
</item>

<item>
	<title>Telekomunikacioni portal | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=271</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=271</guid>
	<description>- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip sajta:&lt;/span&gt; Telekomunikacioni portal&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Detalji:&lt;/span&gt; Jedan od $_GET parametara se stampa u okviru stranice bez filtriranja specijalnih karaktera.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Savet:&lt;/span&gt; Pretvorite specijalne karaktere u odgovarajuce html entitete.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Pronasao&lt;/span&gt;: &lt;a href=&quot;http://netsec.rs/&quot; target=&quot;_blank&quot;&gt;Dejan Levaja&lt;/a&gt;</description>
	<pubDate>Mon, 22 Dec 2008 05:48:00 +0100</pubDate>
</item>

<item>
	<title>Security magazin | RFI</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=268</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=268</guid>
	<description>- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip sajta:&lt;/span&gt; Security magazin&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip propusta:&lt;/span&gt; Remote File Include&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Detalji:&lt;/span&gt; Parametar za biranje frejma stranice prihvata ucitavanje stranica sa udaljenih lokacija.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Savet:&lt;/span&gt; Koristite ucitavanje web stranica preko putanja fajl sistema.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Pronasao&lt;/span&gt;: &lt;a href=&quot;http://netsec.rs/&quot; target=&quot;_blank&quot;&gt;Dejan Levaja&lt;/a&gt;</description>
	<pubDate>Wed, 17 Dec 2008 11:39:21 +0100</pubDate>
</item>

<item>
	<title>Biznis Novine | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=264</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=264</guid>
	<description>&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip sajta:&lt;/span&gt; Online izdanje biznis casopisa&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Detalji:&lt;/span&gt; Logika za prikazivanje gresaka prihvata specijalne html karaktere i stampa ih u okviru poruke o gresci.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Savet:&lt;/span&gt; Pretvorite specijalne karaktere u odgovarajuce html entitete.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Pronasao:&lt;/span&gt; &lt;a target=&quot;_blank&quot; href=&quot;http://www.security-net.biz/&quot;&gt;Ivan Markovic&lt;/a&gt;</description>
	<pubDate>Mon, 08 Dec 2008 05:35:30 +0100</pubDate>
</item>

<item>
	<title>Drzavna institucija | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=257</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=257</guid>
	<description>- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip sajta:&lt;/span&gt; Drzavna institucija&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Detalji:&lt;/span&gt; Parametar za pretragu se stampa direktno u HTML kod stranice.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Savet:&lt;/span&gt; Pretvoriti sve vrednosti koje se stampaju u okviru stranice, u svoje html entitete.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Pronasao&lt;/span&gt;: &lt;a target=&quot;_blank&quot; href=&quot;http://blog.vijatov.com&quot;&gt;Nenad Vijatov&lt;/a&gt;</description>
	<pubDate>Wed, 05 Nov 2008 05:01:18 +0100</pubDate>
</item>

</channel>
</rss>