Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:12955
HistoryJun 03, 2006 - 12:00 a.m.

Weblog Oggi v1.0

2006-06-0300:00:00
vulners.com
8

Weblog Oggi v1.0

Homepage:
http://www.hotwebscripts.com/index.php

User input isn't sanatized before being dynamically generated. For proof of concept just put <IMG
SRC="javascript:alert('XSS');"> in as a comment