Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

EZHomePagePro Multiple Cross-Site Scripting Vulnerabilities


An exploit is not required.

Examples have been provided:

/common/email.asp?page=user&m=y&select=r0t-&usid=2&uname=guest&aname=&adid=[XSS]

/common/email.asp?page=user&m=y&select=r0t-&usid=2&uname=&aname=[XSS]

/users/users_search.asp?page=user&uname=r0t&usid=2&aname=&adid=&m=[XSS]

/users/users_search.asp?page=user&uname=r0t&usid=2&aname=&adid=[XSS]

/users/users_search.asp?page=user&uname=r0t&usid=2&aname=[XSS]

/users/users_calendar.asp?view=yes&action=write&uname=r0t&usid=2&date=3/2/2006&sdate=3/2/2006&page=[XSS]

/users/users_profiles.asp?page=user&uname=r0t&usid=2&aname=&adid=[XSS]

/users/users_profiles.asp?page=user&uname=r0t&usid=2&aname=[XSS]

/users/users_mgallery.asp?gn=r0t&gp=guest&fl=Favorites&usid=[XSS]







 

Privacy Statement
Copyright 2009, SecurityFocus