Tutos File_Select.PHP Cross-Site Scripting Vulnerability
BID:8011
Info
Tutos File_Select.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8011 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2003 12:00AM |
| Updated: | Jun 20 2003 12:00AM |
| Credit: | Discovery credited to François SORIN. |
| Vulnerable: |
Tutos Tutos 1.1 |
| Not Vulnerable: | |
Exploit / POC
Tutos File_Select.PHP Cross-Site Scripting Vulnerability
No exploit is required for this vulnerability.
The following proof-of-concept was provided by François SORIN <[email protected]>:
http://www.example.com/tutos/file/file_select.php?msg=<hostile code>
No exploit is required for this vulnerability.
The following proof-of-concept was provided by François SORIN <[email protected]>:
http://www.example.com/tutos/file/file_select.php?msg=<hostile code>
Solution / Fix
Tutos File_Select.PHP Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Tutos File_Select.PHP Cross-Site Scripting Vulnerability
References:
References:
- Tutos Homepage (Tutos)
- [KSA-001] Multiple vulnerabilities in Tutos (François SORIN
)