exploit-db-mirror/platforms/php/webapps/32669.txt
Offensive Security d39d09c4d0 Updated 04_04_2014
2014-04-04 04:34:07 +00:00

10 lines
No EOL
485 B
Text
Executable file

source: http://www.securityfocus.com/bid/32890/info
The 'phpcksec' script is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
This issue affects phpcksec 0.2.0; other versions may also be affected.
http://www.example.com/path/phpcksec.php?path=>\'><ScRiPt >alert(0);</ScRiPt>