Lucene search

K
exploitdbJanek VindEDB-ID:23745
HistoryFeb 23, 2004 - 12:00 a.m.

XMB Forum 1.8 - 'u2uadmin.php?uid' Cross-Site Scripting

2004-02-2300:00:00
Janek Vind
www.exploit-db.com
20

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/9726/info

XMB Forum has been reported prone to multiple cross-site scripting, HTML injection and SQL injection vulnerabilities. The issues present themselves due to insufficient sanitization of remote user supplied data. An attacker may exploit any one of these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user or to have malicious SQL queries executed in the underlying database.

http://www.example.com/xmb18sp2/u2uadmin.php?uid=x"><%73cript>alert(document.cookie);</%73cript>

AI Score

7.4

Confidence

Low

Related for EDB-ID:23745