PHPOutSourcing Zorum 3.x - Cross-Site Scripting

EDB-ID:

23011


Author:

G00db0y

Type:

webapps


Platform:

PHP

Date:

2003-08-11


source: https://www.securityfocus.com/bid/8388/info

A cross-site scripting vulnerability has been reported in the index.php script of PHPOutSourcing Zorum. Because of this, an attacker may be able to execute HTML and script code in the browsers of target users in the security context of the site hosting the vulnerable script.

http://www.example.com/pathofzorum/index.php?method=<script>alert('test')
</script>