TUCoPS :: Web :: Apps :: b06-2809.htm

Ez Ringtone Manager from scriptez.net - XSS
Ez Ringtone Manager from scriptez.net - XSS
Ez Ringtone Manager from scriptez.net - XSS



Ez Ringtone Manager=0D
=0D
Homepage:=0D
http://www.scriptsez.net=0D 
=0D
Effected files:=0D
player.php=0D
search input box.=0D
=0D
XSS Vulnerabilities:=0D
=0D
http://example.com/ringtones/player.php?action=preview&id=&cat=LG%20Mobiles=0D 
=0D
The search box doesnt properlly filter user input. Tags like