info
discussion
exploit
solution
references
Pixelpost User Comment HTML Injection Vulnerability
An exploit is not required.
An example exploit has been provided:
http://www.example.com/pixelpost/index.php? popup=comment&showimage=1
Add Comment: <XSS>
Privacy Statement
Copyright 2010, SecurityFocus