ExoPHPdesk user profile XSS / profile SQL injection

看板Bugtraq作者時間18年前 (2007/11/14 07:37), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
ExoPHPdesk user profile XSS / profile SQL injection http://exoscripts.com/exohelpdesk You can inject script code into the website area where you create profile. Cookies are in place making an XSS more than possible. http://example.com/helpdesk/index.php?fn=profile&s=&user=admin' sql here SQL injection in the profile area is possible if you choose a bad input.
文章代碼(AID): #17EZL300 (Bugtraq)