10 lines
No EOL
728 B
Text
10 lines
No EOL
728 B
Text
source: https://www.securityfocus.com/bid/8339/info
|
|
|
|
It is possible to create an authentication or access control page, using Dreamweaver MX PHP Authentication Suite. This script will generate an error page that contains dynamic content when a user fails to authenticate correctly to the site.
|
|
|
|
A cross-site-scripting vulnerability has been reported to affect PHP authentication functions used in PHP access control pages created with the Macromedia Dreamweaver MX PHP Authentication Suite.
|
|
|
|
An attacker may exploit this condition to execute arbitrary HTML code in the browser of an unsuspecting user.
|
|
|
|
http://www.example.com/[PATH]/[LOGIN PAGE].php?[ACCESS DENIED VARIABLE]
|
|
="><script>alert('.::\/\|NSRG-18-7|/\/::.');</script> |