AbleDesign D-Man Title Parameter Cross-Site Scripting Vulnerability

No exploit is required.

Proof of concept is available:
http://www.example.com/index.php?go=admin&do=do_search&du=usergroup&title=[code]&search=single


 

Privacy Statement
Copyright 2010, SecurityFocus