Bugtraq mailing list archives
XSS bug in Zorum 2.4
From: Arab VieruZ <arabviersus () hotmail com>
Date: 10 Oct 2002 17:46:58 -0000
Vulnerable systems: Zorum 2.4 Exploit: z_user_show.php?method=showuserlink&class=<Scr*ipt>javascript:alert (document.cookie)</Scr*ipt>&rollid=admin&x=3da59a9da8825& (without "*") Solution: i think that will work , but im not sure open dbtreelistproperty_method.php and put this code in line 7: $class = HTMLSpecialChars($class); i'm a beginer php developer soooory :) ---------------------------------- Arab Vieruz thanx
Current thread:
- XSS bug in Zorum 2.4 Arab VieruZ (Oct 10)