Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

TorrentFlux Startpop.PHP Cross-Site Scripting Vulnerability

TorrentFlux is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue could allow an attacker to execute attacker-supplied script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 2.1 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus