Liens_Dynamiques 2.1 - Multiple Cross-Site Scripting Vulnerabilities

EDB-ID:

29466

CVE:

N/A


Author:

sn0oPy

Type:

webapps


Platform:

PHP

Date:

2007-01-15


source: https://www.securityfocus.com/bid/22070/info

The 'liens_dynamiques' program is prone to multiple cross-site scripting vulnerabilities because the application fails to sufficiently sanitize user-supplied input.

An attacker can exploit these issues to steal cookie-based authentication credentials and launch other attacks.

These issues affect version 2.1; other versions may also be affected. 

http://www.example.com/liens.php3?ajouter=1