Rhino Software Zaep AntiSpam Cross-Site Scripting Vulnerability

No exploit is required to leverage this issue. The following proof of concept has been provided:

http://example.zaep/?key=<script>alert(document.cookie)<%252Fscript>


 

Privacy Statement
Copyright 2010, SecurityFocus