OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Toms Gstebuch 1.00 - XSS

cod3ingmail.com
Date: Sat Sep 01 2007 - 07:27:29 CDT


Software: Guestbook
Title: Toms Gästebuch 1.00
Version: 1.0
Type: XSS
Date: Sat Aug 11 21:52:08 CEST 2007
Vendor: Fitz Thomas
Page: http://www.toms-seiten.at/

vulnerability:
----------------------------
http://example.com/form.php?action=show&homepage=[XSS]&mail=[XSS]&name=[XSS]
http://example.com/admin/header.php?language=[XSS]&anzeigebreite=[XSS]
http://example.com/install.php?msg=[XSS]

The vendor has been informed.