Digital Hive 'base.php' Parameter Cross-Site Scripting Vulnerability

An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.

The following proof-of-concept URI is available:

http://www.example.com/a/hive_v2.RC2/base.php?page=membres.php&mt=[XSS]


 

Privacy Statement
Copyright 2010, SecurityFocus