logo

QoW 1 answered; Qow 2 released

ID: 05600d08-6ad2-5643-a604-890472ea95b9

STIX ID: report--05600d08-6ad2-5643-a604-890472ea95b9

Feed Name: SensePost Blog

Threat Score
30/100

Date Published: 2007-07-24

Date Updated: 2026-04-29

...
...

This SensePost QOW write-up demonstrates a cross-site scripting (XSS) vulnerability where a web form returns submitted name/value pairs in a table, enabling an attacker to split a JavaScript payload across multiple parameters and reassemble it using eval() to exfiltrate cookies or redirect users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.