Bugtraq mailing list archives

phpWebSite XSS Vulnerability


From: Sp.IC <SpeedICNet () Hotmail Com>
Date: 2 Oct 2002 21:59:08 -0000



.:: phpWebSite XSS Vulnerability.

A Cross-Site Scripting vulnerability found in phpWebSite that would allow 
attackers to inject script codes into the page and executing it on the 
clients browser as if it were provided by the site.

• Vulnerable systems:

    - phpWebSite 0.8.3, maybe other versions.

• Example:

article.php?sid="><Img Src=javascript:alert(document.cookie)><Img Src="


Current thread: