|
AlstraSoft E-Friends - XSS =0D
=0D
Homepage: =0D
http://www.alstrasoft.com/ =0D
=0D
Description:=0D
=0D
Alstrasoft E-friends allows you to run a community site like MySpace and Friendster. =0D
=0D
Effected files or areas of site:=0D
index.php =0D
=0D
The input forms on the following items belowdo not properlly filter out all potential harmful characters. XSS are possible because of this. =0D
=0D
Posting a blog=0D
Posting a listing=0D
Posting an event=0D
Adding comments=0D
Sending a message