Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

TalentSoft Web+ Shop Deptname Parameter Cross-Site Scripting Vulnerability

This issue can be exploited through a web client.

The following proof-of-concept URI is available:

http://www.example.com/cgi-bin/webplus.exe?script=/webpshop/department.wml&deptid=3&deptname=[XSS]







 

Privacy Statement
Copyright 2008, SecurityFocus