Abledesign Dynamic Picture Frame XSS

看板Bugtraq作者時間18年前 (2007/08/28 03:09), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Vendor Site: http://abledesign.com/ Version affected: ??? Demo: http://abledesign.com/demo/pframe.php Class: Input Validation Error Overview: Dynamic Picture Frame is a PHP script which allows you to add a variety of picture frames of any size to images on your website. Dynamic Picture Frame fails to sufficiently sanitize user-supplied input data in "Image URL" text box by pressing the "submit" button. Example: 1.<html><font color="Red"><b>XSS</b></font></html> Discovered by: Joshua Morin (morin.josh@gmail.com)
文章代碼(AID): #16qo5S00 (Bugtraq)