Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Updir.net Updir.PHP Cross Site Scripting Vulnerability

Updir.net is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

Exploiting this issue allows an attacker to execute arbitrary HTML or script code in a user's browser session in the context of an affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Versions prior to Updir.net 2.04 are vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus