PHP Live! Multiple Cross-Site Scripting Vulnerabilities

PHP Live! is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Version 3.2.2 was reported vulnerable; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus