about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities


Title DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
Published 2008-02-04-12:00AM
Updated 2008-02-05-11:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Lostmon lords <lostmon@gmail.com> discovered these vulnerabilities.
Vulnerable  EXoops EXoops 1.0.8
bcoos bcoos 1.1.11
Not Vulnerable  
Code  Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.The following proof-of-concept URIs are available:http://www.example.com/modules/devtracker/index.php?proj_id=1&amp;order_by=priority&amp;direction=ASCquot;&gt;&lt;script&gt;alert()&lt;/script&gt; http://www.example.com/modules/devtracker/index.php?proj_id=1&amp;order_by=priorityquot;&gt;&lt;script&gt;alert()&lt;/script&gt;&amp;direction=ASC
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 22 Nov 2008 22:32:06 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
photo hot. string www.regmur NT scanner JPortal IPB 2.3.2 porn tamil Microsoft WWW.indian videosex a www..wap.w /search/ex www.sex88. www.clips1 School gir Sexy grial Porn video namitha se WWW.Sexfot SEX33 realitykin www.asunse www.sexmen AuthMySQL namitha se nude bolly ramesh sex free a pinay sexy add Sexy grial ISLAM-612 actualince mambo Remo news for c Resource teen sex p swou NexentaOS deshibaba@ MySql 5.0. pono star ctt www. phone www.sex600 Indianesex www.sextee New sex vd indian sex IPB 2..2.1