OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Aria-Security] Stuffed Tracker Multiple Cross-Site Scripting VULN

From: AdvisoryAria-Security.Net, (AdvisoryAria-Security.Net)
Date: Thu Oct 04 2007 - 15:18:54 CDT


Aria-Security Team
----------------------
Vendor:
http://stuffedguys.com/

POC:
http://target/path/admin/campaign_link.html?GenCode=1&CampId=1&SplitId=&GLink=XSS
http://target/PATH/actions.html?CpId=1&SiteId=1&Mode=new&EditId=[XSS]

Credits Goes To Aria-Security Team
Regards,
The-0utl4w
http://Aria-Security.Net [Aria-Security's Website]