Since redscull took some time to understand how XSS works (no offence, it just isn't that easy!) I made a proof of concept.
Wc3edit.net now steals the swat account cookie for every user who visits this forum and is logged in his swat account.
This data _doesn't_ allow anyone to access your account (I didn't plan to abuse it) but simply shows the vulnerability.
Here you can see the cookies it logged so far:
http://dekar.wc3edit.net/logger.php
To try it out just make an account at http://night.org/swat2/playerdb/index.php?p=new and visit wc3edit.net after logging in there.
			
			
									
						Wc3edit.net steals swat cookies now - tryout a XSS attack
- 
				Dekar
 - Forum Drunk
 - Posts: 2923
 - Joined: January 17th, 2007, 4:22 pm
 - Has thanked: 1 time
 - Been thanked: 1 time
 
Wc3edit.net steals swat cookies now - tryout a XSS attack
Don't pm me with Warcraft questions, this is a forum so just make a post!
In the world of thinking we are all immigrants. -Robert Nozick
- 
				Hmmz0r
														 - Junior Member
 - Posts: 33
 - Joined: April 16th, 2009, 9:17 pm
 - Title: Peon
 - Location: Sweden
 
Re: Wc3edit.net steals swat cookies now - tryout a XSS attack
I have no idea what this does, but it sounds Dangerous o.O
			
			
									
						Spoiler for Truth: 
- 
				Dekar
 - Forum Drunk
 - Posts: 2923
 - Joined: January 17th, 2007, 4:22 pm
 - Has thanked: 1 time
 - Been thanked: 1 time
 
Re: Wc3edit.net steals swat cookies now - tryout a XSS attack
http://en.wikipedia.org/wiki/Cross-site_scripting
Yeah kinda... could delete/steal data... But I'm not evil
			
			
									
						Yeah kinda... could delete/steal data... But I'm not evil
Don't pm me with Warcraft questions, this is a forum so just make a post!
In the world of thinking we are all immigrants. -Robert Nozick
- 
				Hmmz0r
														 - Junior Member
 - Posts: 33
 - Joined: April 16th, 2009, 9:17 pm
 - Title: Peon
 - Location: Sweden
 
- 
				Dekar
 - Forum Drunk
 - Posts: 2923
 - Joined: January 17th, 2007, 4:22 pm
 - Has thanked: 1 time
 - Been thanked: 1 time
 
Re: Wc3edit.net steals swat cookies now - tryout a XSS attack
Okay the party is over, he finally fixed it 
			
			
									
						Don't pm me with Warcraft questions, this is a forum so just make a post!
In the world of thinking we are all immigrants. -Robert Nozick
