| New User, Welcome! Login |
Abledesign Dynamic Picture Frame XSS
| From: |
morin josh gmail com |
| To: |
bugtraq securityfocus com |
| Cc: |
|
| Subject: |
Abledesign Dynamic Picture Frame XSS |
| Date: |
Sun - Aug 26, 2007 01:09 PM |
Vendor Site: http://abledesign.com/
Version affected: ???
Demo: http://abledesign.com/demo/pframe.php
Class: Input Validation Error
Overview: Dynamic Picture Frame is a PHP script which allows you to add a variety of picture frames of any size to images on your website. Dynamic Picture Frame fails to sufficiently sanitize user-supplied input data in "Image URL" text box by pressing the "submit" button.
Example:
1.<html><font color="Red"><b>XSS</b></font></html>
Discovered by: Joshua Morin (morin.josh@gmail.com)
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!