ETicket Open.PHP Multiple Cross-Site Scripting Vulnerabilities

To exploit these issues, an attacker must entice an authenticated administrator of the application to follow a maliciously crafted URI.

The following proof-of-concept URIs are available:

http://www.example.com/open.php?err=[xss]
http://www.example.com/open.php?warn=[xss]


 

Privacy Statement
Copyright 2010, SecurityFocus