Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:18406
HistoryNov 14, 2007 - 12:00 a.m.

ExoPHPdesk user profile XSS / profile SQL injection

2007-11-1400:00:00
vulners.com
24

ExoPHPdesk user profile XSS / profile SQL injection
http://exoscripts.com/exohelpdesk

You can inject script code into the website area where you create profile. Cookies are in place making an XSS more than possible.

http://example.com/helpdesk/index.php?fn=profile&s=&user=admin' sql here
SQL injection in the profile area is possible if you choose a bad input.