Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHCDownload 'search.php' SQL Injection and Cross-Site Scripting Vulnerability

Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.

The following proof-of-concept URIs are available:

http://www.example.com/[phcdownload/search.php?string=[XSS]
http://www.example.com/[phcdownload/search.php?string='







 

Privacy Statement
Copyright 2008, SecurityFocus