functional security
Showing 1 - 1 of 1 RSS Feed

Files

TaskFreak 0.6.3 Cross Site Scripting
Posted Jun 30, 2010
Site secunia.com

Secunia Research has discovered a vulnerability in TaskFreak, which can be exploited by malicious people to conduct cross-site scripting attacks. Input passed to the "tznMessage" parameter in logout.php is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Version 0.6.3 is affected.

tags | advisory, arbitrary, php, xss
advisories | CVE-2010-1520
MD5 | eda34859a8afb27fe6a6339cc96e40de
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close