|
PHPResidence <= 0.6 XSS=0D
=0D
Discovered by: Nomenumbra=0D
Date: 23/5/2006=0D
impact:moderate (privilege escalation,possible defacement)=0D
=0D
PHP Residence software doesn't sanitize any of it's input,=0D
allowing a malicious attacker (providing he/she has an account)=0D
to inject arbitrary HTML or javascript code=0D
=0D
Nomenumbra