|
Plume CMS 'manager/xmedia.php' Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI. The following proof of concept is available: http://www.example.com/manager/xmedia.php?dir=theme/default/<script>alert("XSS")</script>&mode= |
|
Privacy Statement |