RSS   Vulnerabilities for
'Auto-surf traffic exchange script'
   RSS

2009-12-30
 
CVE-2009-4460

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.

 


Copyright 2017, cxsecurity.com

 

Back to Top