Tagworld XSS
V Wall just sent me an XSS exploit in Tagworld. Tagworld is a community site very similar to MySpace, allowing people to post blogs, post photos and otherwize find someone to take home for a night. What he found was that certain fields allow for common XSS attack strings. This wouldn’t be a big deal except for the meme aspects of community sites.
This could easily pave the way for another SAMY worm. Granted Tagworld is not the same size or scale as MySpace, but given the turnover in these types of sites (Orkut, Friendster, etc…) to new applications there is no reason this couldn’t end up being a big issue if left unpatched. Here are the screenshots V Wall sent me:
Thanks, V Wall!



June 10th, 2006 at 12:39 am
ack, beaten to it!, ah well, good find! V Wall
June 12th, 2006 at 1:37 pm
Thanks Luny, i had fouind it a while back but though id give them time to stick a plaster on it an fix themself, when i came back later on an did a second check i found they had done nothing about it.,
Thats what made my mind up on getting it out in the open