TUCoPS :: Web :: CMS / Portals :: bt-21708.htm

E107 XSS
Cross-Site Scripting vulnerability in E107
Cross-Site Scripting vulnerability in E107



Hello Bugtraq!

I want to warn you about Cross-Site Scripting vulnerability in E107. Which I
found at 31.01.2009 and disclosed recently.

XSS:

At page for sending news to email (http://site/email.php?news.1) it's 
possible to conduct XSS attack via Referer header. Particularly it can be
done via flash.

Referer: '>

Vulnerable are E107 0.7.16 and previous versions (all versions).

I mentioned about this vulnerability at my site
(http://websecurity.com.ua/3528/). 

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua 


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH