Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15202
HistoryNov 23, 2006 - 12:00 a.m.

XSS in scriptat support InverseFlow Help Desk v2.31

2006-11-2300:00:00
vulners.com
24

XSS in scriptat support InverseFlow Help Desk v2.31

::::::::::::::::::::::::::::::::::::::::::::::::::::::

Discovered : SwEET-DeViL & viP HaCkEr & HaCkEr sUn
Name scriptat: InverseFlow Help Desk v2.31
tame : AL-garnei
K-S-A
::::::::::::::::::::::::::::::::::::::::::::::::::::::
####################################################################
[1]

in ticketview.php

http://www.site.com/support_path/ticketview.php?id=[xss]

http://www.site.com/support_path/ticketview.php?email=[xss]

http://www.site.com/support_path/ticketview.php?cmd=deletepost&id=[xss]

http://www.site.com/support_path/ticketview.php?cmd=deletepost&email=[xss]
###################################################################
[2]

in ticket.php

http://www.site.com/support_path/ticket.php?email=[xss]

#################################################################

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

Greetings to all our friends … ;

SwEET-DeViL MiaL is [email protected] or [email protected]