«
Expand/Collapse
3 items tagged "climate and trace"
Related tags:
pi project [+],
education [+],
climate education [+],
arbitrary html [+],
x event,
windows servers,
windows,
video,
usa,
trace results,
trace details,
sql queries,
sql,
separate page,
science event,
science,
root directory,
read all,
paper,
northwest passage,
northeast passage,
mark burnett,
mac os x,
mac os,
james c. foster mark burnett,
james c foster,
hackers,
forensic,
file,
fearing,
engineering,
david weston tags,
david weston,
chaos communication congress,
black hat,
axd,
authors,
audio,
arctic sea ice,
arctic sea,
arctic,
Pentesting
-
-
8:55
»
Packet Storm Security Exploits
The Tri-Agency Climate Education (TrACE) Catalog provides search and browse access to a catalog of educational products and resources. TrACE focuses on climate education resources that have been developed by initiatives funded through NASA, NOAA, and NSF, comprising a tri-agency collaboration around climate education. The application suffers from a reflected cross site scripting vulnerability when input is passed to the 'product_id', 'pi', 'project_id' and 'funder' GET parameters in 'trace_results.php' script which is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Version 1.0 is affected.
-
8:55
»
Packet Storm Security Recent Files
The Tri-Agency Climate Education (TrACE) Catalog provides search and browse access to a catalog of educational products and resources. TrACE focuses on climate education resources that have been developed by initiatives funded through NASA, NOAA, and NSF, comprising a tri-agency collaboration around climate education. The application suffers from a reflected cross site scripting vulnerability when input is passed to the 'product_id', 'pi', 'project_id' and 'funder' GET parameters in 'trace_results.php' script which is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Version 1.0 is affected.
-
8:55
»
Packet Storm Security Misc. Files
The Tri-Agency Climate Education (TrACE) Catalog provides search and browse access to a catalog of educational products and resources. TrACE focuses on climate education resources that have been developed by initiatives funded through NASA, NOAA, and NSF, comprising a tri-agency collaboration around climate education. The application suffers from a reflected cross site scripting vulnerability when input is passed to the 'product_id', 'pi', 'project_id' and 'funder' GET parameters in 'trace_results.php' script which is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Version 1.0 is affected.