about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , BlogPHP Multiple HTML Injection, Cross-Site Scripting and Cookie Manipulation Vulnerabilities


Title BlogPHP Multiple HTML Injection, Cross-Site Scripting and Cookie Manipulation Vulnerabilities
Published 2008-05-10-12:00AM
Updated 2008-05-10-12:00AM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  David Sopas Ferreira
Vulnerable  BlogPHP BlogPHP 2.0
Not Vulnerable  
Code  Attackers can exploit these issues via a web browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a malicious URI.The following proof-of-concept for the cross-site scripting issue is available:http://www.example.com/index.php?act=sendmessage&user=admin[XSS]
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 16:32:56 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
/search/ex Www.Ultrap com_linkdi maxcpm.inf Webmin%252 www.kk-net news for c news for c woman and www.kk-net dchub ...Shells news for c apache 2.0 www.japang news for C www.world News Searc PORENO PORENO www.szsfa. sexygerls news for c www.Avezoo WWW. Pink www.japang 200 /compo Animasi na module sex video news for c www.ecodee /search/ex news+for+c www.ecodee sex movie WWW27SEX.C ratbox //classifi 200 /compo wwwtamilse news for c www.nyblg. grand-shin dmoz.im dmoz.im namidasexy news for c fadiha nan WWWSEX.COM