about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , All Enthusiast PhotoPost PHP Pro Multiple Cross-Site Scripting Vulnerabilities


Title All Enthusiast PhotoPost PHP Pro Multiple Cross-Site Scripting Vulnerabilities
Published 2005-01-04-12:00AM
Updated 2005-01-04-05:37PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to James Bercegay of the GulfTech Security Research Team.
Vulnerable  All Enthusiast Inc Photopost PHP Pro 4.8.1
All Enthusiast Inc Photopost PHP Pro 4.6
All Enthusiast Inc Photopost PHP Pro 4.1
All Enthusiast Inc Photopost PHP Pro 4.0
All Enthusiast Inc Photopost PHP Pro 3.3
All Enthusiast Inc Photopost PHP Pro 3.2
All Enthusiast Inc Photopost PHP Pro 3.1
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept examples are available:
http://www.example.com/showgallery.php?cat=[INT]&page=[XSS]
http://www.example.com/showgallery.php?si=[XSS]
http://www.example.com/showgallery.php?cat=[INT][XSS]
http://www.example.com/showgallery.php?ppuser=[INT]&cat=[INT][XSS]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 12:44:07 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
moroco /search/ex www.pinkwo www.sexyph free vedio meta sploi 5FP0G1FOKA www.cp101. Bollywoods PHP HTML.h babam& p bot DS-2002 sqjfzx.com www.cnbatt www.skuai. maxcpm.inf sexmovirs Nude sexy milf in ne holiday2tr telugusexc prizm Saniamirza punbb Images.Sex auth by pa windows xp kansas lo44l WoltLab news for c Rassi bia2 kate winsl Trishas se wu-ftpd-2. smf hack dotnet fra www.byiis. sex gy %2Fcompone Www.sax.co php shell all cartoo fucking pu kernel 2.6 events 1.2 %2Fcompone components