邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2005-8-25 03:30

[转载]Nephp Publisher企业版跨站脚本攻击漏洞

信息来源:[url]www.shabgard.org[/url]

Home : [url]http://www.nephp.com[/url]
Type : Validation
Description : Vulnerable to Cross Site Scripting (XSS) attacks.
-------------------------------------------------------------------------
example :

/nephp/browse.php?mod=find&keywords='%3E%3Cscript%3Ealert('test');%3C/script%3E


bl2k
Greetz : strcpy,Hergy,magic,mouse,Littlehacker ...

页: [1]
© 1999-2008 EvilOctal Security Team