Lucene search

K
exploitdbHackers Center SecurityEDB-ID:29341
HistoryDec 25, 2006 - 12:00 a.m.

PHP Live! 3.2.2 phplive/message_box.php Multiple Parameter XSS

2006-12-2500:00:00
Hackers Center Security
www.exploit-db.com
24

EPSS

0.032

Percentile

91.4%

PHP Live! 3.2.2 phplive/message_box.php Multiple Parameter XSS. CVE-2006-6769. Webapps exploit for php platform

source: http://www.securityfocus.com/bid/21737/info
  
PHP Live! is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input. 
  
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
  
Version 3.2.2 was reported vulnerable; other versions may also be affected.

/phplive/message_box.php?theme=&l=ezpub&x=1&deptid=[XSS]
/phplive/message_box.php?theme=&l=admin&x=[XSS]

EPSS

0.032

Percentile

91.4%

Related for EDB-ID:29341